CVE-2025-64706

MEDIUM

Typebot < 3.13.0 - Improper Access Control

Title source: rule
STIX 2.1

Description

Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Object Reference (IDOR) vulnerability exists in the API token management endpoint. An authenticated attacker can delete any user's API token and retrieve its value by simply knowing the target user's ID and token ID, without requiring authorization checks. Version 3.13.0 fixes the issue.

References (1)

Core 1
Core References

Scores

CVSS v3 5.0
EPSS 0.0005
EPSS Percentile 13.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-639
Status published
Products (1)
typebot/typebot 3.9.0 - 3.13.0
Published Nov 13, 2025
Tracked Since Feb 18, 2026