@typebot.io/js
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @typebot.io/jspage 1 of 1
- CVE-2025-65098HIGHCVSS 7.4EG 7.4✓ Fixed in 0.9.152026-01-22
Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credentials from any user. When a victim previews a malicious typebot by clicking "Run", JavaScript …
- CVE-2026-28445HIGHCVSS 8.7EG 8.7✓ Fixed in 0.10.12026-05-22
Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders the user-controlled customIcon.svg field directly via Solid's innerHTML directive without any sanitization, even thoug…
- CVE-2026-39964MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.10.12026-05-22
TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor tags from rich text bubble content without filtering the javascript: URI scheme. A bot author can set a link URL to java…
Check whether @typebot.io/js is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @typebot.io/js CVEs against the assets you own.
Start Free Scan →