CRITICAL 9.6 NVD

CVE-2026-47705

TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or esc

TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or escape user-supplied input when generating CSV files. An attacker can inject spreadsheet formulas into input fields, which are later executed when an administrator opens the exported CSV in spreadsheet software such as Microsoft Excel or LibreOffice Calc. Version 3.17.0 patches the issue.

References

Published: 2026-08-11 · Source: NVD · Feed updated: 2026-08-11
This critical severity vulnerability with a CVSS score of 9.6 was published on 2026-08-11 via NVD.

Risk Timeline

CVE Disclosed2026-08-11 · -1 days ago

Remediation Resources

vulnfeed aggregates 10022 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.