HIGH7.4npm
GHSA-4xc5-wfwc-jw47· CVE-2025-65098Typebot affected by Credential Theft via Client-Side Script Execution and API Authorization Bypass
Modified: 2/3/2026
package
pkg:npm/%40typebot.io/js
Typebot affected by Credential Theft via Client-Side Script Execution and API Authorization Bypass
Modified: 2/3/2026
Typebot has Stored XSS via Rating Block Custom Icon that Bypasses isUnsafe Sandbox in Builder Preview
Modified: 9/10/2026
Typebot.io has stored XSS via `javascript`: URI in text bubble links — bot author executes JS on visitors' browsers
Modified: 9/10/2026