Skip to content

CVE-2026-48768

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
June 18, 2026
Last Seen
June 18, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical vulnerability, CVE-2026-48768, was disclosed affecting TypeBot versions 3.16.1 and earlier. The flaw allows unauthenticated users to exploit the POST /api/blocks/file-input/v3/generate-upload-url endpoint, which improperly handles unsanitized fileName inputs. This enables anonymous visito...

Public Exploits

Checking GitHub for proof-of-concept code…