{"id":"CVE-2026-48494","aliases":["GHSA-fqf7-mmp5-j3jq"],"url":"https://o3.security/vulnerability/CVE-2026-48494","summary":"TypeBot vulnerable to cross-typebot WhatsApp preview webhook resume via global `wa-preview-{phone}` session ids","details":"TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resume a WhatsApp preview webhook session that belongs to a different typebot by mixing an authorized `typebotId` and `blockId` and a foreign preview phone number tied to another preview session. The WhatsApp test-webhook handler authorizes the parent typebot first, but then resolves the preview chat session only by `wa-preview-{phone}`. As a result, an attacker can inject arbitrary webhook JSON into another workspace's WhatsApp preview session and advance its draft/unpublished flow without any access to the victim typebot. Version 3.17.0 patches the issue.","published":"2026-08-11T17:09:33.029Z","modified":"2026-08-13T04:02:52.955706706Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/baptisteArno/typebot.io/commit/36a618610174fd168fb255d9c8ecc0d2cf61a192","label":"baptisteArno/typebot.io@36a6186"},"references":[{"type":"WEB","url":"https://github.com/baptisteArno/typebot.io/releases/tag/v3.17.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48494.json"},{"type":"ADVISORY","url":"https://github.com/baptisteArno/typebot.io/security/advisories/GHSA-fqf7-mmp5-j3jq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48494"},{"type":"FIX","url":"https://github.com/baptisteArno/typebot.io/commit/36a618610174fd168fb255d9c8ecc0d2cf61a192"},{"type":"FIX","url":"https://github.com/baptisteArno/typebot.io/pull/2499"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-13T04:02:52.955706706Z"}}