logo

Critical CVE-2026-48768 Vulnerability in TypeBot Exposes Users to File Upload Attacks

ID: 14a76b15-d12e-59e0-b24d-746413a34cb7

STIX ID: report--14a76b15-d12e-59e0-b24d-746413a34cb7

Feed Name: ThreatCluster

Threat Score
80/100

Date Published: 2026-06-18

Date Updated: 2026-06-22

...
...

A critical vulnerability (CVE-2026-48768) affecting TypeBot versions 3.16.1 and earlier allows unauthenticated users to exploit the `POST /api/blocks/file-input/v3/generate-upload-url` endpoint by supplying unsanitized `fileName` inputs, enabling uploads of malicious HTML, SVG, or JS files to arbitrary S3 object paths across tenants; the flaw was published on June 17, 2026, and requires immediate mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.