What is CVE-2026-48765?
CVE-2026-48765 in TypeBot before version 3.17.0 allows a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and overwrite it via `handleUpdateOAuthCredentials()`. This poses an unauthorized workspace access risk; users should upgrade to the latest version.
Azərbaycanca: TypeBot chatbot qurucusunda aşkar edilən CVE-2026-48765, 3.17.0 versiyasından əvvəl aşağı səlahiyyətli read collaborator-un bot konfiqurasiyasındakı OAuth `credentialsId`-ni oxuyaraq, `handleUpdateOAuthCredentials()` funksiyası vasitəsilə onu dəyişdirməsinə imkan verir. Bu, iş sahəsinə icazəsiz giriş riski yaradır, istifadəçilər TypeBot-u ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of TypeBot chatbot builder are affected by CVE-2026-48765?
CVE-2026-48765 affects TypeBot versions prior to 3.17.0.
What risky action can a low-privilege collaborator perform by exploiting CVE-2026-48765?
A low-privilege read collaborator can extract an OAuth `credentialsId` from a bot configuration and overwrite it via `handleUpdateOAuthCredentials()`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.