TypeBot disclosed CVE-2026-47705, a high-severity CSV injection flaw in version 3.16.1 that allowed attacker-controlled input in exported results to be written to CSV files without proper sanitization or escaping. If an administrator opened a malicious export in spreadsheet software such as Microsoft Excel or LibreOffice Calc, injected formulas could execute, potentially leading to compromise of confidentiality, integrity, and availability. The issue is tracked as CWE-1236 and carries the CVSS v3.1 vector AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H.
The vulnerability was fixed in TypeBot 3.17.0 through changes merged into the main branch in pull request #2493, titled "Sanitize CSV exports against formula injection." The patch introduced or updated a sanitizeCsvCell routine and modified export-related components including streamAllResultsToCsv, streamAllResultsToCsvV2, SelectionToolbar, and ExportAllResultsDialog, indicating the remediation focused on preventing spreadsheet formula payloads from being preserved in exported result files.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE entry states the vulnerability was newly received by security-advisories@github.com as CVE-2026-47705. The issue describes a CSV injection flaw in TypeBot 3.16.1's result export feature.
Baptiste Arnaud merged pull request #2493 and commit 89682dd into the main branch to sanitize CSV exports against formula injection in TypeBot's result export functionality. The change introduced or modified sanitization logic for dangerous spreadsheet-leading characters and affected export-related components.
CVE-2026-47705 was disclosed as a CSV injection vulnerability affecting TypeBot 3.16.1, where unsanitized user input in exported CSV files could execute formulas when opened in spreadsheet software. The advisory states that TypeBot version 3.17.0 fixes the issue and references the related GitHub advisory, fixing commit, pull request, and release tag.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.