TypeBot vulnerable to CSV injection in result export
Summary
| CVE | CVE-2026-47705 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-11 18:17:27 UTC |
| Updated | 2026-08-11 18:17:27 UTC |
| Description | TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or escape user-supplied input when generating CSV files. An attacker can inject spreadsheet formulas into input fields, which are later executed when an administrator opens the exported CSV in spreadsheet software such as Microsoft Excel or LibreOffice Calc. Version 3.17.0 patches the issue. |
Risk And Classification
Primary CVSS: v3.1 9.6 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Problem Types: CWE-1236 | CWE-1236 CWE-1236: Improper Neutralization of Formula Elements in a CSV File
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.6 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 9.6 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | BaptisteArno | Typebot.io | affected = 3.16.1 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/baptisteArno/typebot.io/releases/tag/v3.17.0 | [email protected] | github.com | |
| github.com/baptisteArno/typebot.io/pull/2493 | [email protected] | github.com | |
| github.com/baptisteArno/typebot.io/commit/89682dd4ad56f33263332fa377beb0... | [email protected] | github.com | |
| github.com/baptisteArno/typebot.io/security/advisories/GHSA-p52m-h5qg-8p8w | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.