What is CVE-2026-48762?
CVE-2026-48762 affects TypeBot, a chatbot builder tool. In versions prior to 3.16.0, the OpenAI "Create Transcription" action fetches a user-supplied audio URL using `fetch()` without the SSRF protection present elsewhere, allowing attackers to make arbitrary HTTP requests from the server. Upgrade to version 3.16.0 or later to remediate this Server-Side Request Forgery vulnerability.
Azərbaycanca: CVE-2026-48762 TypeBot chatbot qurucusunda aşkarlanıb. 3.16.0 versiyasından əvvəlki versiyalarda, OpenAI "Create Transcription" funksiyası istifadəçi tərəfindən verilən audio URL-i `fetch()` ilə götürərkən, kodun digər hissələrində mövcud olan SSRF mühafizəsini tətbiq etmir. Bu, hücumçunun serveri manipulyasiya edərək ixtiyari daxili şəbəkə resurslarına HTTP sorğuları göndərməsinə imkan verə bilər. TypeBot-u 3.16.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of TypeBot are affected by CVE-2026-48762?
This vulnerability affects all versions of TypeBot prior to 3.16.0.
Through which function can the CVE-2026-48762 SSRF vulnerability be exploited in TypeBot?
The vulnerability lies in the OpenAI "Create Transcription" action, where a user-supplied audio URL is fetched using `fetch()` without the SSRF protection being applied.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.