Skip to main content

CVE-2024-30264

8.1
HIGHCVSS v3.1 Base Score
0.74%
LOW RiskEPSS (73rd percentile)

Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prior to version 2.24.0 may allow an attacker to hijack a user's account. The sign-in page takes the `redirectPath` parameter from the URL. If a user clicks on a link where the `redirectPath` parameter has a javascript scheme, the attacker that crafted the link may be able to execute arbitrary JavaScript with the privileges of the user. Version 2.24.0 contains a patch for this issue.

Published: 4/4/2024
Modified: 1/30/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.1HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

EPSS Score (Exploitation Probability)

0.74%LOW Exploitation Risk
73rd percentile

This vulnerability has a 0.74% probability of being exploited in the next 30 days, ranking higher than 73% of all scored CVEs.

Related Vulnerabilities