CVE-2025-64706

Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Object Reference (IDOR) vulnerability exists in the API token management endpoint. An authenticated attacker can delete any user's API token and retrieve its value by simply knowing the target user's ID and token ID, without requiring authorization checks. Version 3.13.0 fixes the issue.
Configurations

No configuration.

History

13 Nov 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-13 18:15

Updated : 2025-11-14 16:42


NVD link : CVE-2025-64706

Mitre link : CVE-2025-64706

CVE.ORG link : CVE-2025-64706


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control

CWE-639

Authorization Bypass Through User-Controlled Key