NONE · 0

CVE-2026-47702

TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings. An attacker who gain...

Vulnerability Description

TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings. An attacker who gains read access to the database (e.g., via SQL injection, backup exposure, or insider access) can extract all API tokens and impersonate any user without requiring a password or multi-factor authentication. Version 3.17.0 fixes the issue.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-47702?

CVE-2026-47702 is a documented vulnerability. TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings. An attacker who gain...

How severe is CVE-2026-47702?

CVSS scoring is not yet available for CVE-2026-47702. Check NVD for updates.

Is there a patch for CVE-2026-47702?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.