PT-2026-42822 · Typebot · Typebot

CVE-2026-39970

·

Published

2026-05-22

·

Updated

2026-05-23

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TypeBot versions prior to 3.16.0
Description The application contains a stored Cross-Site Scripting (XSS) issue in the profile picture upload form at the 'app.typebot.io' endpoint. The system fails to sanitize or restrict SVG/XML-based uploads and renders them directly. An attacker can upload a crafted SVG file containing embedded JavaScript to execute arbitrary code in the browsers of victims. Because the payload is persistently stored on the infrastructure and accessible via a permanent public link, this can lead to session or token theft, account takeover, and exfiltration of sensitive user data.
Recommendations Update to version 3.16.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39970
GHSA-JJ87-C343-26VP

Affected Products

Typebot