CVE-2026-39966
TypeBot is a chatbot builder tool. In versions 3.15.2, the getLinkedTypebots API endpoint returns full bot definitions to any authenticated user who references a target bot ID in a Typebot Link block, regardless of workspace ownership, leading to IDOR. The authorization check uses Array.filter() with an async callback β since filter() is synchronous, the callback always returns a truthy Promise, so the access control predicate is never actually evaluated. Any authenticated Typebot user can read the full definition of any other workspace's private bots, including: all conversation blocks and logic flow, variable values embedded in the bot (credentials, API keys, PII), webhook URLs and integration configurations. This issue has been fixed in version 3.16.0.
- Affected products
- Typebot
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.3% (17th percentile)
- Weakness
- CWE-863
- NVD status
- Deferred
- Published
- 2026-05-22
No indexed exploits for CVE-2026-39966 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-39966 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows β not that no exploit exists.