CVE-2026-42142
TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not valida
CVSS
7.1
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-862
Not enough EPSS history yet.
TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate workspace membership, allowing any authenticated user to access and decrypt another workspace's Google Sheets OAuth credentials and retrieve spreadsheet data (sheet names, IDs, column headers). Version 3.17.0 fixes the issue.
- github.comhttps://github.com/baptisteArno/typebot.io/commit/91d2a986d942232b98c066fc460d7c48c04a464b
- github.comhttps://github.com/baptisteArno/typebot.io/pull/2467
- github.comhttps://github.com/baptisteArno/typebot.io/releases/tag/v3.17.0
- github.comhttps://github.com/baptisteArno/typebot.io/security/advisories/GHSA-7jr4-r73c-h4h9
- github.comhttps://github.com/baptisteArno/typebot.io/security/advisories/GHSA-7jr4-r73c-h4h9
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-703408.1 HIG—
———Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.6hCVE-2026-658066.5 MED—
———Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.6hCVE-2026-629156.5 MED—
———Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.6hCVE-2026-619365.5 MED—
———Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.6hCVE-2026-591138.8 HIG—
———Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.6hCVE-2026-403756.5 MED—
———Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.6h