Baptiste Arnaud
9 exploits
Active since Apr 2024
TypeBot has SSRF in HTTP request and script fetch flows via DNS rebinding bypass
CVSS 8.2
TypeBot: Async filter() bypasses authorization, allowing IDOR in getLinkedTypebots and leaking cross-workspace bot definitions
CVSS 6.5
TypeBot: Cross-Typebot Result Data Access via Missing typebotId Filter
CVSS 3.1
TypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview Endpoint
CVSS 7.1
Typebot: IDOR in Result Logs Endpoint Allows Cross-Workspace Data Disclosure
CVSS 6.5
Typebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in Builder Preview
CVSS 8.7
TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request Validation
CVSS 7.6
TypeBot: Stored XSS via javascript: URI in text bubble links — bot author executes JS on visitors' browsers
CVSS 5.4
typebot < 2.24.0 - Reflected Cross-Site Scripting via Sign-In Page redirectPath Parameter
CVSS 8.1