What is CVE-2026-47769?
CVE-2026-47769 is a critical vulnerability found in APIFold. The flaw allows the `/webhooks/:serverSlug/:eventName` endpoint to accept unauthenticated arbitrary JSON and store it in Redis, which could lead to malicious data injection. Immediate update to the latest commit is recommended for mitigation.
Azərbaycanca: CVE-2026-47769 APIFold alətində aşkarlanmış kritik boşluqdur. Bu zəiflik `/webhooks/:serverSlug/:eventName` uç nöqtəsində autentifikasiya olunmamış ixtiyari JSON qəbuluna imkan verərək, Redisə zərərli məlumat yazılmasına səbəb olur. Təhlükəsizlik tədbiri olaraq dərhal ən son commit-ə yeniləmə tövsiyə olunur.
FAQ2
Which component of APIFold is affected by CVE-2026-47769?
The vulnerability affects the `/webhooks/:serverSlug/:eventName` endpoint.
How is CVE-2026-47769 exploited?
A threat actor can send arbitrary JSON without authentication, which is then stored in Redis, leading to malicious data injection.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.