Summary
CVE-2026-62862 is a critical authentication-bypass vulnerability in Typebot’s self-hosted passwordless email login flow, allowing an anonymous, unauthenticated attacker to take over any user account by brute-forcing the 6-digit email verification code. The flaw affects self-hosted Typebot deployments running versions prior to 3.18.0 and carries a CVSS base score of 9.1 (Critical).
Technical details
- Root cause: Typebot generates its 6-digit login codes using
Math.floor(100000 + Math.random() * 900000), a non-cryptographic PRNG that limits the keyspace to 900,000 possible values instead of using NextAuth’s cryptographically secure tokens. - The verification callback (
GET /api/auth/callback/nodemailer) enforces no attempt limit, no lockout, and no CSRF protection, so an attacker can submit unlimited code guesses within the 10-minute validity window. - Failed guesses do not invalidate or consume the outstanding valid code, so the correct code remains guessable for its full lifetime.
- The rate limiter that throttles code-sending trusts the client-controlled
X-Forwarded-Forheader, letting an attacker rotate this header to request multiple concurrent valid codes for the same target email and improve brute-force odds. - Attack vector: network, no authentication or user interaction required. Impact: full account takeover, exposing the victim’s bots, results data, and integration credentials; can also be used to pre-create accounts for arbitrary email addresses.
Affected software
- baptisteArno/typebot.io versions prior to 3.18.0 (self-hosted deployments using the email/passwordless login provider)
Severity
- CVSS v4.0 Base Score: 9.1 (Critical)
- Vector:
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Upgrade self-hosted Typebot instances to version 3.18.0 or later, which addresses the weak token generation, missing rate limiting, and spoofable rate-limit header issues.
- If patching is not immediately possible: disable or restrict the passwordless email login provider, enforce strict server-side rate limiting on the
/api/auth/callback/nodemailerendpoint that does not rely on client-supplied headers, and monitor authentication logs for repeated failed verification attempts against the same account.

