Critical CVE-2026-48768 Vulnerability in TypeBot Exposes Users to File Upload Attacks
ID: 14a76b15-d12e-59e0-b24d-746413a34cb7
STIX ID: report--14a76b15-d12e-59e0-b24d-746413a34cb7
Feed Name: ThreatCluster
Threat Score
A critical vulnerability (CVE-2026-48768) affecting TypeBot versions 3.16.1 and earlier allows unauthenticated users to exploit the `POST /api/blocks/file-input/v3/generate-upload-url` endpoint by supplying unsanitized `fileName` inputs, enabling uploads of malicious HTML, SVG, or JS files to arbitrary S3 object paths across tenants; the flaw was published on June 17, 2026, and requires immediate mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
