CVE-2026-48763: CWE-862: Missing Authorization in baptisteArno typebot.io
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a presigned S3 `PUT` URL for that exact key. Because the endpoint only checks that the referenced typebot is public and that the referenced block is a file input block, an unauthenticated attacker who knows a valid public `typebotId` and `blockId` can request presigned upload URLs for arbitrary objects in the shared bucket, including `private/...` and other tenants' `public/...` paths. Version 3.17.0 fixes this issue.
AI Analysis
Technical Summary
TypeBot.io versions before 3.17.0 expose a deprecated public upload endpoint at GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url that accepts an attacker-controlled filePath parameter and returns a presigned S3 PUT URL for that exact key. The endpoint only verifies that the referenced typebot is public and that the block is a file input block, lacking proper authorization checks. This allows unauthenticated attackers who know valid public typebotId and blockId values to request presigned upload URLs for arbitrary objects in the shared S3 bucket, including private and other tenants' public paths. The vulnerability is fixed in version 3.17.0.
Potential Impact
An unauthenticated attacker can upload arbitrary files to the shared S3 bucket used by TypeBot, including to private and other tenants' public storage paths. This can lead to unauthorized data modification or injection of malicious content. The confidentiality of data is not impacted, but integrity is compromised. Availability impact is low.
Mitigation Recommendations
Version 3.17.0 of TypeBot fixes this vulnerability by removing or securing the deprecated public upload endpoint. Since TypeBot is a cloud service, the vendor manages remediation server-side. Users should ensure they are using version 3.17.0 or later. Patch status is confirmed as fixed in 3.17.0.
CVE-2026-48763: CWE-862: Missing Authorization in baptisteArno typebot.io
Description
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a presigned S3 `PUT` URL for that exact key. Because the endpoint only checks that the referenced typebot is public and that the referenced block is a file input block, an unauthenticated attacker who knows a valid public `typebotId` and `blockId` can request presigned upload URLs for arbitrary objects in the shared bucket, including `private/...` and other tenants' `public/...` paths. Version 3.17.0 fixes this issue.
CVSS v3.1
Score 8.2high
Affected software
pkg:github/baptistearno/typebot.ioRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
TypeBot.io versions before 3.17.0 expose a deprecated public upload endpoint at GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url that accepts an attacker-controlled filePath parameter and returns a presigned S3 PUT URL for that exact key. The endpoint only verifies that the referenced typebot is public and that the block is a file input block, lacking proper authorization checks. This allows unauthenticated attackers who know valid public typebotId and blockId values to request presigned upload URLs for arbitrary objects in the shared S3 bucket, including private and other tenants' public paths. The vulnerability is fixed in version 3.17.0.
Potential Impact
An unauthenticated attacker can upload arbitrary files to the shared S3 bucket used by TypeBot, including to private and other tenants' public storage paths. This can lead to unauthorized data modification or injection of malicious content. The confidentiality of data is not impacted, but integrity is compromised. Availability impact is low.
Mitigation Recommendations
Version 3.17.0 of TypeBot fixes this vulnerability by removing or securing the deprecated public upload endpoint. Since TypeBot is a cloud service, the vendor manages remediation server-side. Users should ensure they are using version 3.17.0 or later. Patch status is confirmed as fixed in 3.17.0.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-22T19:39:05.356Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Is Cloud Service
- true
Threat ID: 6a7b901dbf8831d5396b81bb
Added to database: 08/11/2026, 21:11:57 UTC
Last enriched: 08/11/2026, 21:26:08 UTC
Last updated: 09/07/2026, 10:52:09 UTC
Views: 33
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.