PT-2025-46903 · Typebot · Typebot

Published

2025-11-13

·

Updated

2026-01-30

·

CVE-2025-64709

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Typebot versions prior to 3.13.1
Description Typebot is an open-source chatbot builder. A Server-Side Request Forgery (SSRF) issue exists in the Typebot webhook block (HTTP Request component) functionality. This allows authenticated users to make arbitrary HTTP requests from the server, including access to AWS Instance Metadata Service (IMDS). By bypassing IMDSv2 protection through custom header injection, attackers can extract temporary AWS IAM credentials for the EKS node role, potentially leading to complete compromise of the Kubernetes cluster and associated AWS infrastructure.
Recommendations Update Typebot to version 3.13.1 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-64709
GHSA-8GQ9-RW7V-3JPR

Affected Products

Typebot