CVE-2026-39969
published 2026-05-22CVE-2026-39969: TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST…
PriorityP341medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.14%
3.8th percentile
TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/workspaces/{workspaceId}/whatsapp/{credentialsId}/webhook) does not verify the x-hub-signature-256 HMAC signature included by Meta in every webhook delivery. The webhook URL exposes both workspaceId and credentialsId as path parameters, which are logged in web server access logs, visible in Meta's webhook configuration dashboard, and potentially shared when configuring integrations. This allows any unauthenticated attacker to send spoofed webhook messages to trigger bot flows, consume API resources, and interact with external services using the workspace owner's credentials. The issue has been fixed in version 3.17.0.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| baptistearno | typebot.io | < 3.17.0 | 3.17.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
cvelistv5v3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
baptisteArno typebot.io up to 3.16.x Webhook Message webhook improper authentication (GHSA-8vqp-r5w7-v47f)
vuldb·2026-05-23
CVE-2026-39969 [CRITICAL] baptisteArno typebot.io up to 3.16.x Webhook Message webhook improper authentication (GHSA-8vqp-r5w7-v47f)
A vulnerability was found in baptisteArno typebot.io up to 3.16.x and classified as critical. This impacts an unknown function of the file /v1/workspaces/{workspaceId}/whatsapp/{credentialsId}/webhook of the component Webhook Message Handler. Such manipulation leads to improper authentication.
This vulnerability is traded as CVE-2026-39969. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
CVEList
TypeBot: WhatsApp Webhook Endpoint Missing Signature Verification
cvelistv5·2026-05-22·CVSS 6.5
CVE-2026-39969 [MEDIUM] CWE-287 TypeBot: WhatsApp Webhook Endpoint Missing Signature Verification
TypeBot: WhatsApp Webhook Endpoint Missing Signature Verification
TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/workspaces/{workspaceId}/whatsapp/{credentialsId}/webhook) does not verify the x-hub-signature-256 HMAC signature included by Meta in every webhook delivery. The webhook URL exposes both workspaceId and credentialsId as path parameters, which are logged in web server access logs, visible in Meta's webhook configuration dashboard, and potentially shared when configuring integrations. This allows any unauthenticated attacker to send spoofed webhook messages to trigger bot flows, consume API resources, and interact with external services using the workspace owner's credentials. The issue has been fixed in version
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-22
Published