PT-2026-50572 · Typebot · Typebot

·

CVE-2026-48764

·

Published

2026-06-17

·

Updated

2026-06-18

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions TypeBot versions prior to 3.17.2
Description TypeBot contains a Server-Side Request Forgery (SSRF) flaw in its HTTP request and script fetch flows. The issue stems from a time-of-check to time-of-use gap in the SSRF guard, where the validator resolves a hostname to check for forbidden IP ranges but does not pin that validated IP to the subsequent network connection. This allows an attacker to use DNS rebinding—a technique where a domain name is configured to return different IP addresses in successive DNS queries—to bypass validation. By supplying a URL to a public bot that performs a server-side HTTP Request block or server-side script fetch, an attacker can force the server to connect to private network services, cloud metadata endpoints, or other internal HTTP targets. Potential impacts include metadata disclosure, access to internal admin panels, and credential theft from metadata services.
Recommendations Update to version 3.17.2.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48764
GHSA-HGQQ-WHF5-MRRF

Affected Products

Typebot