CVE 9.6 CRITICAL

Typebot May Expose AWS EKS Credentials via Server Side Request Forgery in Webhook Block_CVE-2025-64709

9.6 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Description

Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerability in the Typebot webhook block (HTTP Request component) functionality allows authenticated users to make arbitrary HTTP requests from the server, including access to AWS Instance Metadata Service (IMDS). By bypassing IMDSv2 protection through custom header injection, attackers can extract temporary AWS IAM credentials for the EKS node role, leading to complete compromise of the Kubernetes cluster and associated AWS infrastructure. Version 3.13.1 fixes the issue.

AI Analysis

Server-Side Request Forgery (SSRF) vulnerability in Typebot webhook block allowing arbitrary HTTP requests and potential extraction of AWS IAM credentials

Basic Information

ID CVE-2025-64709
Source GitHub_M
Published Nov 13, 2025 at 19:42
Modified Nov 13, 2025 at 19:53

Affected Product

Vendor baptisteArno
Product typebot.io
Version < 3.13.1
Affected Versions baptisteArno typebot.io < 3.13.1

CWE Classification

AI Assessment

AI Score 9.6 / 10
AI Severity Critical
Vendor baptisteArno
Product Typebot
Version < 3.13.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.