PT-2025-46903 · Typebot · Typebot
Published
2025-11-13
·
Updated
2026-01-30
·
CVE-2025-64709
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Typebot versions prior to 3.13.1
Description
Typebot is an open-source chatbot builder. A Server-Side Request Forgery (SSRF) issue exists in the Typebot webhook block (HTTP Request component) functionality. This allows authenticated users to make arbitrary HTTP requests from the server, including access to AWS Instance Metadata Service (IMDS). By bypassing IMDSv2 protection through custom header injection, attackers can extract temporary AWS IAM credentials for the EKS node role, potentially leading to complete compromise of the Kubernetes cluster and associated AWS infrastructure.
Recommendations
Update Typebot to version 3.13.1 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typebot