CVE-2026-48768: TypeBot: Unauthenticated arbitrary s3 object write in generate-upload-url via unsanitized fileName

Published Jun 17, 2026
·
Updated

TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses unsanitized fileName input to construct public/ S3 object keys, while issuing presigned PUT URLs that do not bind Content-Type. As a result, any anonymous visitor to a published bot with a file input can upload attacker-controlled HTML, SVG, or JS to attacker-chosen subpaths, including other tenants’ publicly served result paths, enabling arbitrary content hosting and potential stored XSS on the storage origin. ../ traversal is blocked by S3/MinIO canonicalization (signature mismatch), but forward-slash path injection is exploitable. This issue has been fixed in version 3.17.0.

Affected Software

1 affected component
Typebot Typebot<=3.16.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade TypeBot to a version that resolves this vulnerability.

    Fixed in 3.17.0

Event History

Jun 17, 2026
CVE Published
via MITRE·11:13 PM
Data Sourced
via MITRE·11:13 PM
DescriptionSeverityWeakness
Jun 18, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-48768?

CVE-2026-48768 has a critical severity rating of 9.3.

2

How do I fix CVE-2026-48768?

To fix CVE-2026-48768, update TypeBot to version 3.17.0 or later.

3

What impact does CVE-2026-48768 have on TypeBot?

CVE-2026-48768 allows unauthenticated users to write arbitrary files to S3, potentially leading to data exposure.

4

Which versions of TypeBot are affected by CVE-2026-48768?

CVE-2026-48768 affects TypeBot versions 3.16.1 and earlier.

5

What type of vulnerability is CVE-2026-48768 categorized as?

CVE-2026-48768 is categorized as a Path Traversal and XSS vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203