baptistearno
Cloud & SaaSunknown
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting baptistearno.
- CVE-2026-48763TypeBot has Arbitrary S3 Object Write in deprecated public upload endpoint via attacker-controlled filePath8.2
- CVE-2026-48762TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription Handler5.4
- CVE-2026-48765TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials via missing object binding9.9
- CVE-2026-47705TypeBot vulnerable to CSV injection in result export9.6
- CVE-2026-48767Google Sheets OAuth access token disclosure to guest members via getAccessToken7.6
- CVE-2026-48483TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot server5.4
- CVE-2026-48495TypeBot Google Sheets OAuth callback can create credentials in unauthorized workspaces and modify arbitrary typebots7.1
- CVE-2026-48766TypeBot vulnerable to OpenAI API key exfiltration in listModels via attacker-controlled baseUrl7.6
- CVE-2026-42142TypeBot has Authorization Bypass in Google Sheets `getSheets` Endpoint that Allows Cross-Workspace Credential Access7.1
- CVE-2026-49213TypeBot: SSRF protection bypass via IPv6 unspecified address in Typebot HTTP request execution8.1
- CVE-2026-48764TypeBot has SSRF in HTTP request and script fetch flows via DNS rebinding bypass8.2
- CVE-2026-48768TypeBot: Unauthenticated arbitrary s3 object write in generate-upload-url via unsanitized fileName9.3
- CVE-2026-48759TypeBot: Cross-Workspace Theme Template IDOR (Modification and Deletion)7.1
- CVE-2026-39969TypeBot: WhatsApp Webhook Endpoint Missing Signature Verification6.5
- CVE-2026-39967TypeBot: Cross-Typebot Result Data Access via Missing typebotId Filter3.1