Baptiste Arnaud
10 exploits
Active since Apr 2024
TypeBot: SSRF protection bypass via IPv6 unspecified address in Typebot HTTP request execution
CVSS 8.1
TypeBot has SSRF in HTTP request and script fetch flows via DNS rebinding bypass
CVSS 8.2
TypeBot: Async filter() bypasses authorization, allowing IDOR in getLinkedTypebots and leaking cross-workspace bot definitions
CVSS 6.5
TypeBot: Cross-Typebot Result Data Access via Missing typebotId Filter
CVSS 3.1
TypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview Endpoint
CVSS 7.1
Typebot: IDOR in Result Logs Endpoint Allows Cross-Workspace Data Disclosure
CVSS 6.5
Typebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in Builder Preview
CVSS 8.7
TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request Validation
CVSS 7.6
TypeBot: Stored XSS via javascript: URI in text bubble links — bot author executes JS on visitors' browsers
CVSS 5.4
typebot < 2.24.0 - Reflected Cross-Site Scripting via Sign-In Page redirectPath Parameter
CVSS 8.1