CVE-2025-65098: Typebot

High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credentials from any user. When a victim previews a malicious typebot by clicking "Run", JavaScript executes in their browser and exfiltrates their OpenAI keys, Google Sheets tokens, and SMTP passwords. The `/api/trpc/credentials.getCredentials` endpoint returns plaintext API keys without verifying credential ownership. Version 3.13.2 fixes the issue.

Affected products

  • Typebot Typebot: before 3.13.2 (fixed in 3.13.2)

Published 2026-01-22. Last modified 2026-06-17.