What is CVE-2026-48763?
CVE-2026-48763 affects TypeBot chatbot builder versions prior to 3.17.0. A deprecated public endpoint (`GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url`) allows an attacker to supply a `filePath` and receive a presigned S3 `PUT` URL for that key. Users should upgrade to version 3.17.0 or later immediately.
Azərbaycanca: CVE-2026-48763 TypeBot chatbot qurucusunda müəyyən edilib. 3.17.0-dan əvvəlki versiyalarda köhnə ictimai upload endpoint (`GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url`) vasitəsilə təcavüzkar `filePath` parametrini idarə edərək presigned S3 `PUT` URL-i əldə edə bilər. TypeBot istifadəçiləri dərhal 3.17.0 və ya daha yuxarı versiyaya yeniləməlidir.
FAQ1
Which versions of TypeBot are affected by CVE-2026-48763?
This vulnerability affects TypeBot versions prior to 3.17.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.