CVE-2026-28444: CWE-639: Authorization Bypass Through User-Controlled Key in baptisteArno typebot.io
Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint authorizes the caller against the provided typebotId but fetches logs solely by resultId without verifying that the result belongs to the authorized typebot, leading to IDOR. An authenticated attacker can supply their own typebotId alongside any victim's resultId to read execution logs from other workspaces, leaking sensitive data including HTTP response bodies, AI model outputs, and webhook payloads. Every other result-scoped endpoint in the same router properly validates that the resultId belongs to the authorized typebotId. This confirms the missing check is an oversight, not a design choice. This issue has been fixed in version 3.15.2.
AI Analysis
Technical Summary
In typebot.io versions before 3.16.0, the getResultLogs API endpoint suffers from an Insecure Direct Object Reference (IDOR) due to missing validation that the resultId belongs to the authorized typebotId. While the endpoint authorizes callers against the provided typebotId, it retrieves logs solely by resultId without confirming ownership, enabling an authenticated attacker to read logs from other users' workspaces. This leads to unauthorized disclosure of sensitive data including HTTP response bodies, AI model outputs, and webhook payloads. Other result-scoped endpoints correctly enforce this validation, confirming this was an implementation oversight. The vulnerability is fixed in version 3.16.0.
Potential Impact
An authenticated attacker can bypass authorization controls to access execution logs from other users' workspaces, resulting in exposure of sensitive information such as HTTP response bodies, AI model outputs, and webhook payloads. This unauthorized data disclosure can compromise confidentiality but does not affect integrity or availability.
Mitigation Recommendations
Upgrade typebot.io to version 3.16.0 or later, where the vulnerability has been fixed by adding proper validation to ensure that the resultId belongs to the authorized typebotId. No other mitigation is indicated or required.
CVE-2026-28444: CWE-639: Authorization Bypass Through User-Controlled Key in baptisteArno typebot.io
Description
Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint authorizes the caller against the provided typebotId but fetches logs solely by resultId without verifying that the result belongs to the authorized typebot, leading to IDOR. An authenticated attacker can supply their own typebotId alongside any victim's resultId to read execution logs from other workspaces, leaking sensitive data including HTTP response bodies, AI model outputs, and webhook payloads. Every other result-scoped endpoint in the same router properly validates that the resultId belongs to the authorized typebotId. This confirms the missing check is an oversight, not a design choice. This issue has been fixed in version 3.15.2.
CVSS v3.1
Score 6.5medium
Affected software
pkg:github/baptistearno/typebot.ioRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In typebot.io versions before 3.16.0, the getResultLogs API endpoint suffers from an Insecure Direct Object Reference (IDOR) due to missing validation that the resultId belongs to the authorized typebotId. While the endpoint authorizes callers against the provided typebotId, it retrieves logs solely by resultId without confirming ownership, enabling an authenticated attacker to read logs from other users' workspaces. This leads to unauthorized disclosure of sensitive data including HTTP response bodies, AI model outputs, and webhook payloads. Other result-scoped endpoints correctly enforce this validation, confirming this was an implementation oversight. The vulnerability is fixed in version 3.16.0.
Potential Impact
An authenticated attacker can bypass authorization controls to access execution logs from other users' workspaces, resulting in exposure of sensitive information such as HTTP response bodies, AI model outputs, and webhook payloads. This unauthorized data disclosure can compromise confidentiality but does not affect integrity or availability.
Mitigation Recommendations
Upgrade typebot.io to version 3.16.0 or later, where the vulnerability has been fixed by adding proper validation to ensure that the resultId belongs to the authorized typebotId. No other mitigation is indicated or required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-02-27T15:54:05.140Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a10847be1370fbb481eba5b
Added to database: 05/22/2026, 16:29:47 UTC
Last enriched: 05/22/2026, 16:44:57 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 70
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.