Sploitus

CVE-2026-47704

No indexed exploits for CVE-2026-47704 yet

TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read access to any typebot can resume a waiting webhook session that belongs to a different typebot by mixing an authorized `typebotId` and `blockId` and a foreign live `resultId`. The webhook resume handler authorizes the parent typebot first, but then resolves the descendant `result` only by `resultId`. As a result, an attacker can inject arbitrary webhook JSON into another typebot's suspended session and advance its execution without any access to the victim typebot. Version 3.17.0 patches the issue.

Affected products
Typebot
Fix
Available
CVSS 4.0
7.1 HIGH
EPSS
0.5% (43th percentile)
Weakness
CWE-639
NVD status
Received
Published
2026-08-11
CVE-2026-47704 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-47704 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-47704 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.