CVE-2025-64709
CRITICALtypebot < 3.13.1 - Authenticated Server-Side Request Forgery via Webhook Block
Title source: llmDescription
Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerability in the Typebot webhook block (HTTP Request component) functionality allows authenticated users to make arbitrary HTTP requests from the server, including access to AWS Instance Metadata Service (IMDS). By bypassing IMDSv2 protection through custom header injection, attackers can extract temporary AWS IAM credentials for the EKS node role, leading to complete compromise of the Kubernetes cluster and associated AWS infrastructure. Version 3.13.1 fixes the issue.
References (1)
Core 1
Core References
Exploit, Mitigation, Vendor Advisory x_refsource_confirm
https://github.com/baptisteArno/typebot.io/security/advisories/GHSA-8gq9-rw7v-3jpr
Scores
CVSS v3
9.6
EPSS
0.0033
EPSS Percentile
24.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-918
Status
published
Products (1)
typebot/typebot
< 3.13.1
Published
Nov 13, 2025
Tracked Since
Feb 18, 2026