9.6
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Description
Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerability in the Typebot webhook block (HTTP Request component) functionality allows authenticated users to make arbitrary HTTP requests from the server, including access to AWS Instance Metadata Service (IMDS). By bypassing IMDSv2 protection through custom header injection, attackers can extract temporary AWS IAM credentials for the EKS node role, leading to complete compromise of the Kubernetes cluster and associated AWS infrastructure. Version 3.13.1 fixes the issue.
AI Analysis
Server-Side Request Forgery (SSRF) vulnerability in Typebot webhook block allowing arbitrary HTTP requests and potential extraction of AWS IAM credentials
Basic Information
ID
CVE-2025-64709
Source
GitHub_M
Published
Nov 13, 2025 at 19:42
Modified
Nov 13, 2025 at 19:53
Affected Product
Vendor
baptisteArno
Product
typebot.io
Version
< 3.13.1
Affected Versions
baptisteArno typebot.io < 3.13.1
CWE Classification
AI Assessment
AI Score
9.6 / 10
AI Severity
Critical
Vendor
baptisteArno
Product
Typebot
Version
< 3.13.1