Sploitus

CVE-2025-65098

No indexed exploits for CVE-2025-65098 yet

Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credentials from any user. When a victim previews a malicious typebot by clicking "Run", JavaScript executes in their browser and exfiltrates their OpenAI keys, Google Sheets tokens, and SMTP passwords. The `/api/trpc/credentials.getCredentials` endpoint returns plaintext API keys without verifying credential ownership. Version 3.13.2 fixes the issue.

Affected products
Typebot
Typebot
< 3.13.2
Fix
Available
CVSS 3.1
7.4 HIGH
EPSS
0.3% (22th percentile)
Weakness
CWE-862, CWE-200, CWE-639, CWE-284, CWE-522, CWE-311, CWE-79
NVD status
Analyzed
Published
2026-01-22
CVE-2025-65098 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-65098 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-65098 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.