← volver
CVE-2026-39969

TypeBot: WhatsApp Webhook Endpoint Missing Signature Verification

CVSS 6.5 MEDIUMEPSS 0.1%CWE-287CWE-345
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.5EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
22 may 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/workspaces/{workspaceId}/whatsapp/{credentialsId}/webhook) does not verify the x-hub-signature-256 HMAC signature included by Meta in every webhook delivery. The webhook URL exposes both workspaceId and credentialsId as path parameters, which are logged in web server access logs, visible in Meta's webhook configuration dashboard, and potentially shared when configuring integrations. This allows any unauthenticated attacker to send spoofed webhook messages to trigger bot flows, consume API resources, and interact with external services using the workspace owner's credentials. The issue has been fixed in version 3.17.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Productos afectados
baptisteArno · typebot.io

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →