PT-2026-42822 · Typebot · Typebot
CVE-2026-39970
·
Published
2026-05-22
·
Updated
2026-05-23
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TypeBot versions prior to 3.16.0
Description
The application contains a stored Cross-Site Scripting (XSS) issue in the profile picture upload form at the 'app.typebot.io' endpoint. The system fails to sanitize or restrict SVG/XML-based uploads and renders them directly. An attacker can upload a crafted SVG file containing embedded JavaScript to execute arbitrary code in the browsers of victims. Because the payload is persistently stored on the infrastructure and accessible via a permanent public link, this can lead to session or token theft, account takeover, and exfiltration of sensitive user data.
Recommendations
Update to version 3.16.0.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typebot