MEDIUM 6.4 NVD
CVE-2026-62861
TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenticated non-guest workspace member can remove another workspace's public custom domain and make ty
TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenticated non-guest workspace member can remove another workspace's public custom domain and make typebots on that domain unavailable. The custom-domain delete handler in handleDeleteCustomDomain.ts authorizes a caller against a client-supplied workspaceId but sends the client-supplied domain name to the shared Vercel project before verifying that the domain belongs to that workspace. This issue is fixed in version 3.18.0.
References
- https://github.com/baptisteArno/typebot.io/commit/06575dfcd461ba76071012869d4b1f4046f9a6b8
- https://github.com/baptisteArno/typebot.io/releases/tag/v3.18.0
- https://github.com/baptisteArno/typebot.io/security/advisories/GHSA-7h82-p425-wpmg
This medium severity vulnerability with a CVSS score of 6.4 was published on 2026-08-25 via NVD.
vulnfeed aggregates 11369 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.