CVE-2026-39970Active Exploitation

MEDIUMCVSS 8.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.typebot.io profile picture upload form. The application fails to sanitize or restrict SVG/XML-based uploads and directly renders them when accessed through the domain. By uploading a crafted malicious SVG file containing embedded JavaScript, an attacker will execute arbitrary JavaScript code. This vulnerability directly enables stored XSS exploitation because the payload is persistently stored on your infrastructure (app.typebot.io) and accessible from a public-facing, permanent link. Stored XSS via malicious SVG uploads to app.typebot.io allows attackers to execute arbitrary JavaScript in victims' browsers, enabling session/token theft, account takeover, and exfiltration of sensitive user data. This issue has been fixed in version 3.16.0.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-05-23); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-23: 1Mentions · 2026-06-08: 1Mentions · 2026-06-09: 1Mentions · 2026-06-12: 1Active Exploitation · 2026-05-23: 1Patch / Workaround · 2026-06-08: 1Technical Details · 2026-06-08: 105-2306-0806-0906-12
Signal classification4 categories
Active Exploitation
125.0%
Patch
125.0%
General
125.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-231
Active Exploitation1
2026-06-081
Patch1
2026-06-091
General1
2026-06-121
Disclosure1
Full discourse4 posts
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    CVE-2026-39970 TypeBot バージョン3.15.2以前の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/06/cve-2026-39970-typebot-3152/ #IT #Security #cybersecurity

    Post summary

    The text points to a Japanese article that explains a TypeBot vulnerability affecting versions before 3.15.2, discussing impact and mitigation, but offers no PoC, exploit details, patch information, or evidence of active exploitation.

    0000030
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    CVE-2026-39970 TypeBot バージョン3.15.2以前の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/06/cve-2026-39970-typebot-3152/ #IT #Security #cybersecurity

    Post summary

    An article outline describes a vulnerability affecting TypeBot versions ≤3.15.2, but provides no technical details, exploit code, patch, or evidence of active attacks.

    0000028
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    CVE-2026-39970 TypeBot バージョン3.15.2以前の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/06/cve-2026-39970-typebot-3152/ #IT #Security #cybersecurity

    Post summary

    An article explaining the TypeBot vulnerability (CVE‑2026‑39970) provides technical details and discusses patches and mitigations, but does not mention PoC, exploit code, or active exploitation.

    0000049
    209 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    It is possible to see elevated activities targeting baptisteArno http://typebot.io (CVE-2026-39970) https://vuldb.com/vuln/365262/cti

    Post summary

    The post indicates that there may be active attacks against CVE-2026-39970, but it lacks concrete proof of exploitation, technical details, or patch information.

    0000056
    2.2K followersView on X

Explore more