Sploitus

CVE-2026-62861

No indexed exploits for CVE-2026-62861 yet

TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenticated non-guest workspace member can remove another workspace's public custom domain and make typebots on that domain unavailable. The custom-domain delete handler in handleDeleteCustomDomain.ts authorizes a caller against a client-supplied workspaceId but sends the client-supplied domain name to the shared Vercel project before verifying that the domain belongs to that workspace. This issue is fixed in version 3.18.0.

Affected products
Typebot
Fix
Available
CVSS 4.0
6.4 MEDIUM
EPSS
0.4% (33th percentile)
Weakness
CWE-639, CWE-862
NVD status
Received
Published
2026-08-25
CVE-2026-62861 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-62861 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-62861 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.