Impact
TypeBot’s SSRF validator rejects many local and private addresses but mistakenly permits the IPv6 unspecified address `::`, allowing an attacker with access to modify a workspace’s server‑side HTTP request block or guarded script fetch to force the Typebot server to connect to internal HTTP services. When a chat is started or continued via the exposed API endpoints, the server can reach services that should be isolated, thus enabling the attacker to read or interact with internal resources.
Affected Systems
Any installation of TypeBot v3.17.1 or earlier that is actively hosting workspace editors or creators capable of configuring server‑side request blocks or guarded script fetches is vulnerable. The issue is resolved from release 3.17.2 onward.
Risk and Exploitability
The vulnerability has a CVSS score of 8.1, indicating high severity, but its EPSS score is less than 1% and the bug is not listed in the CISA KEV catalog, suggesting limited known exploitation. Nevertheless, the attack is straightforward for anyone who can alter the workspace configuration, enabling the Typebot server to connect to internal endpoints and potentially expose sensitive data.
OpenCVE Enrichment