Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A Server-Side Request Forgery vulnerability (CVE-2026-48764, CWE-918) has been reported in Typebot (baptisteArno/typebot.io), an open-source chatbot builder platform. If exploited, an attacker could force the typebot server to issue internal HTTP requests, potentially reaching cloud metadata endpoints, internal APIs, or configuration services not intended to be externally accessible. The affected version range is unconfirmed from authoritative sources; organizations running self-hosted typebot deployments should treat this as a priority pending vendor confirmation.

Author

Tech Jacks Solutions