
CVE-2026-48768 in TypeBot chatbot builder allows unauthenticated users to upload attacker-controlled HTML, SVG or JS files via the /api/blocks/file-input/v3/generate-upload-url endpoint in versions 3.16.1 and earlier, http://cve.report disclosed. #ThreatIntel #CyberSecurity https://t.co/i14RqxpGmR
Post summary
CVE-2026-48768 is a newly disclosed vulnerability in the TypeBot chatbot builder that allows unauthenticated users to upload attacker‑controlled HTML, SVG, and JS files via a specific API endpoint. The issue was reported on cve.report, with no mention of active exploitation or patches yet.



