PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39964 baptisteArno CVE debrief

The CVE record for CVE-2026-39964 was published on 2026-05-22T18:16:21.690Z and has not been modified since then. The NVD entry is currently Deferred. This cross-site scripting vulnerability in TypeBot chatbot builder versions prior to 3.16.0 allows an attacker to execute JavaScript code in the visitor's browser context when a link is clicked, which can result in the exfiltration of cookies and session tokens. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. Users of TypeBot chatbot builder versions prior to 3.16.0 should be aware of this vulnerability and take steps to defend against cross-site scripting attacks.

Vendor
baptisteArno
Product
typebot.io
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-22
Original CVE updated
2026-07-23
Advisory published
2026-05-22
Advisory updated
2026-07-23

Who should care

Users of TypeBot chatbot builder versions prior to 3.16.0 should be aware of this vulnerability and take steps to defend against cross-site scripting attacks. This includes inventorying and checking for affected versions, applying vendor remediation by upgrading to version 3.16.0 or later, implementing compensating controls such as input validation and output encoding, and monitoring for suspicious activity.

Technical summary

CVE-2026-39964 is a cross-site scripting vulnerability in TypeBot chatbot builder versions prior to 3.16.0. The vulnerability allows an attacker to execute JavaScript code in the visitor's browser context when a link is clicked, which can result in the exfiltration of cookies and session tokens. The vulnerability is caused by the Typebot viewer rendering anchor tags from rich text bubble content without filtering the javascript: URI scheme. A bot author can set a link URL to javascript:PAYLOAD, which executes in the visitor's browser context when clicked.

Defensive priority

Medium

Recommended defensive actions

  • Inventory and check for TypeBot chatbot builder versions prior to 3.16.0
  • Apply vendor remediation by upgrading to version 3.16.0 or later
  • Implement compensating controls such as input validation and output encoding
  • Monitor for suspicious activity and implement exception tracking
  • Review and update incident response plans to address potential cross-site scripting attacks
  • Conduct regular security audits to identify and address potential vulnerabilities
  • Provide training to developers and users on secure coding practices and vulnerability management

Evidence notes

The CVE record and NVD entry provide evidence of the vulnerability and its impact. However, further analysis is needed to fully understand the scope of the vulnerability and the affected systems. The vulnerability allows an attacker to execute JavaScript code in the visitor's browser context when a link is clicked, which can result in the exfiltration of cookies and session tokens. The TypeBot chatbot builder tool is affected by this vulnerability in versions prior to 3.16.0. The CVE record was published on 2026-05-22T18:16:21.690Z and has not been modified since then. The NVD entry is currently Deferred. To verify the vulnerability, defenders should review the official advisory and CVE record.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-22T18:16:21.690Z and has not been modified since then. The NVD entry is currently Deferred.