CVE-2026-42142
TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate workspace membership, allowing any authenticated user to access and decrypt another workspace's Google Sheets OAuth credentials and retrieve spreadsheet data (sheet names, IDs, column headers). Version 3.17.0 fixes the issue.
- Affected products
- Typebot
- Fix
- Available
- CVSS 3.1
- 7.1 HIGH
- EPSS
- 0.3% (19th percentile)
- Weakness
- CWE-862
- NVD status
- Received
- Published
- 2026-08-11
CVE-2026-42142 at NVD
No indexed exploits for CVE-2026-42142 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-42142 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.