Summary
CVE-2026-48763 is a missing authorization vulnerability (CWE-862) in Typebot, an open-source chatbot builder, affecting versions prior to 3.17.0. A deprecated public upload endpoint issues presigned S3 URLs without verifying that the requested object path belongs to the legitimate public bot context, allowing an unauthenticated attacker to write to arbitrary objects in the shared storage bucket. The issue carries a CVSS v3.1 base score of 8.2 (High).
Technical details
- Root cause: the endpoint
GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-urlaccepts a caller-suppliedfilePathparameter and forwards it unchanged to the S3 presign function, without restricting it to a namespace tied to the requesting bot. - Trigger conditions: the endpoint only checks that the referenced typebot is public and that the referenced block is a file input block; it performs no check that the supplied
filePathbelongs to that bot or workspace. - Attack vector: network, unauthenticated. An attacker only needs to know a valid public
typebotIdand a file-inputblockIdto request presigned upload URLs. - Impact: presigned
PUTURLs can be obtained for arbitrary keys in the shared bucket, includingprivate/...paths and other tenants’public/...paths, enabling creation or overwrite of objects in workspaces the attacker does not control. Impact is limited to integrity (high) and availability (low); confidentiality is not affected per the CVSS vector.
Affected software
- Typebot (baptisteArno/typebot.io) — all versions prior to 3.17.0
Severity
- CVSS v3.1 Base Score: 8.2 (High)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Mitigation and recommended actions
- Immediate: upgrade Typebot to version 3.17.0 or later, which removes/fixes the deprecated public upload endpoint’s authorization logic.
- If immediate patching is not possible: restrict or disable external access to the
/api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-urlendpoint at the network or reverse-proxy layer, and audit shared S3 bucket contents for unexpected or unauthorized objects.
How IONIX identifies potentially affected assets
IONIX matches the following signal against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
| Typebot

