CVE-2025-65098 affects Typebot versions prior to 3.13.2, an open-source chatbot builder. This vulnerability allows for client-side script execution, enabling an attacker to steal sensitive credentials like OpenAI keys, Google Sheets tokens, and SMTP passwords when a user previews a malicious typebot. Rated 7.4 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N), the attack requires user interaction (UI:R) but has low attack complexity (AC:L) and results in high confidentiality impact (C:H). There is no evidence of active exploitation, nor are there public exploit modules like Metasploit or Nuclei, though it has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.13.2CPE matchmatch criteria | cpe:2.3:a:typebot:typebot:*:*:*:*:*:-:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.