CVE-2026-48763 | BaptisteArno TypeBot up to 3.16.1 upload-url filePath unrestricted upload
A vulnerability labeled as critical has been found in BaptisteArno TypeBot up to 3.16.1. Affected by this issue is some unknown functionality of the file /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url. Such manipulation of the argument filePath leads to unrestricted upload.
This vulnerability is traded as CVE-2026-48763. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More