PT-2026-50572 · Typebot · Typebot
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TypeBot versions prior to 3.17.2
Description
TypeBot contains a Server-Side Request Forgery (SSRF) flaw in its HTTP request and script fetch flows. The issue stems from a time-of-check to time-of-use gap in the SSRF guard, where the validator resolves a hostname to check for forbidden IP ranges but does not pin that validated IP to the subsequent network connection. This allows an attacker to use DNS rebinding—a technique where a domain name is configured to return different IP addresses in successive DNS queries—to bypass validation. By supplying a URL to a public bot that performs a server-side HTTP Request block or server-side script fetch, an attacker can force the server to connect to private network services, cloud metadata endpoints, or other internal HTTP targets. Potential impacts include metadata disclosure, access to internal admin panels, and credential theft from metadata services.
Recommendations
Update to version 3.17.2.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typebot