CVE-2025-64706

Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Object Reference (IDOR) vulnerability exists in the API token management endpoint. An authenticated attacker can delete any user's API token and retrieve its value by simply knowing the target user's ID and token ID, without requiring authorization checks. Version 3.13.0 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:typebot:typebot:*:*:*:*:*:-:*:*

History

30 Jan 2026, 14:14

Type Values Removed Values Added
CPE cpe:2.3:a:typebot:typebot:*:*:*:*:*:-:*:*
References () https://github.com/baptisteArno/typebot.io/security/advisories/GHSA-grx8-g27p-8hpp - () https://github.com/baptisteArno/typebot.io/security/advisories/GHSA-grx8-g27p-8hpp - Exploit, Vendor Advisory
First Time Typebot
Typebot typebot

13 Nov 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-13 18:15

Updated : 2026-01-30 14:14


NVD link : CVE-2025-64706

Mitre link : CVE-2025-64706

CVE.ORG link : CVE-2025-64706


JSON object : View

Products Affected

typebot

  • typebot
CWE
CWE-284

Improper Access Control

CWE-639

Authorization Bypass Through User-Controlled Key