{"id":"CVE-2026-48494","summary":"TypeBot vulnerable to cross-typebot WhatsApp preview webhook resume via global `wa-preview-{phone}` session ids","details":"TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resume a WhatsApp preview webhook session that belongs to a different typebot by mixing an authorized `typebotId` and `blockId` and a foreign preview phone number tied to another preview session. The WhatsApp test-webhook handler authorizes the parent typebot first, but then resolves the preview chat session only by `wa-preview-{phone}`. As a result, an attacker can inject arbitrary webhook JSON into another workspace's WhatsApp preview session and advance its draft/unpublished flow without any access to the victim typebot. Version 3.17.0 patches the issue.","aliases":["GHSA-fqf7-mmp5-j3jq"],"modified":"2026-08-13T04:02:52.955706706Z","published":"2026-08-11T17:09:33.029Z","database_specific":{"cwe_ids":["CWE-639"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48494.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/baptisteArno/typebot.io/releases/tag/v3.17.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48494.json"},{"type":"ADVISORY","url":"https://github.com/baptisteArno/typebot.io/security/advisories/GHSA-fqf7-mmp5-j3jq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48494"},{"type":"FIX","url":"https://github.com/baptisteArno/typebot.io/commit/36a618610174fd168fb255d9c8ecc0d2cf61a192"},{"type":"FIX","url":"https://github.com/baptisteArno/typebot.io/pull/2499"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/baptistearno/typebot.io","events":[{"introduced":"c5a8c850269cad2ee65cd043f1045fba63cc99d0"},{"fixed":"36a618610174fd168fb255d9c8ecc0d2cf61a192"},{"fixed":"31c360a342e40d1423e5421c046e8f821b1154c4"}],"database_specific":{"extracted_events":[{"introduced":"= 3.16.1"},{"last_affected":"= 3.16.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["= 3.16.1","react-v0.10.2","js-v0.10.2","v3.16.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48494.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}