logo

Critical CVE-2026-48768 Vulnerability in TypeBot Exposes Users to File Upload Attacks

ID: c5c61b13-e221-5529-957c-f4fd5e186b75

STIX ID: report--c5c61b13-e221-5529-957c-f4fd5e186b75

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

...
...

A critical vulnerability (CVE-2026-48768) in TypeBot versions 3.16.1 and earlier permits unauthenticated attackers to exploit the POST /api/blocks/file-input/v3/generate-upload-url endpoint by providing unsanitized fileName input, enabling uploads of malicious HTML, SVG, or JS to arbitrary S3 object paths across tenants; organizations using affected versions must assess exposure and remediate immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.