CVE-2025-64706

MEDIUM

typebot 3.9.0-3.12.9 - Authenticated Insecure Direct Object Reference in API Token Management

Title source: llm
STIX 2.1

Description

Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Object Reference (IDOR) vulnerability exists in the API token management endpoint. An authenticated attacker can delete any user's API token and retrieve its value by simply knowing the target user's ID and token ID, without requiring authorization checks. Version 3.13.0 fixes the issue.

References (1)

Core 1
Core References

Scores

CVSS v3 5.0
EPSS 0.0020
EPSS Percentile 10.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-639
Status published
Products (1)
typebot/typebot 3.9.0 - 3.13.0
Published Nov 13, 2025
Tracked Since Feb 18, 2026