CVE-2026-48763
Last modified
CVE-2026-48763 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a presigned S3 `PUT` URL for that exact key.
Description
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a presigned S3 `PUT` URL for that exact key. Because the endpoint only checks that the referenced typebot is public and that the referenced block is a file input block, an unauthenticated attacker who knows a valid public `typebotId` and `blockId` can request presigned upload URLs for arbitrary objects in the shared bucket, including `private/...` and other tenants' `public/...` paths. Version 3.17.0 fixes this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| baptisteArno | typebot.io | < 3.17.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-48763?
How severe is CVE-2026-48763?
How do I fix CVE-2026-48763?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-48758sigstore-js provides JavaScript libraries for interacting wi…5.4
- CVE-2026-48759TypeBot is a chatbot builder tool. Versions 3.15.2 and below…7.1
- CVE-2026-4876A vulnerability was identified in itsourcecode Free Hotel Re…6.3
- CVE-2026-48760Symfony is a PHP framework for web and console applications …6.1
- CVE-2026-48761Symfony is a PHP framework for web and console applications …6.1
- CVE-2026-48762TypeBot is a chatbot builder tool. Prior to version 3.16.0, …5.4
- CVE-2026-48764TypeBot is a chatbot builder tool. In versions prior to 3.17…8.2
- CVE-2026-48765TypeBot is a chatbot builder tool. Versions prior to 3.17.0 …9.9
- CVE-2026-48766TypeBot is a chatbot builder tool. Versions prior to 3.17.0 …7.6
- CVE-2026-48767TypeBot is a chatbot builder tool. Versions prior to 3.17.0 …7.6
- CVE-2026-48768TypeBot is a chatbot builder tool. In versions 3.16.1 and ea…9.3
- CVE-2026-4877A security flaw has been discovered in itsourcecode Payroll …4.3
Are you affected by CVE-2026-48763?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
