CVEs we hold for Baptistearno
Records whose assigning authority named Baptistearno as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-62865TypeBot: Arbitrary server file read via Send Email block attachment pathbaptisteArno typebot.io
CVE-2026-62862TypeBot: Account takeover via brute-forceable 6-digit magic-link codebaptisteArno typebot.io
CVE-2026-62861TypeBot: Cross-tenant custom-domain removal via unbound `name` in handleDeleteCustomDomainbaptisteArno typebot.io
CVE-2026-49213TypeBot: SSRF protection bypass via IPv6 unspecified address in Typebot HTTP request executionbaptisteArno typebot.io
CVE-2026-48768TypeBot: Unauthenticated arbitrary s3 object write in generate-upload-url via unsanitized fileNamebaptisteArno typebot.io
CVE-2026-48767Google Sheets OAuth access token disclosure to guest members via getAccessTokenbaptisteArno typebot.io
CVE-2026-48766TypeBot vulnerable to OpenAI API key exfiltration in listModels via attacker-controlled baseUrlbaptisteArno typebot.io
CVE-2026-48765TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials via missing object bindingbaptisteArno typebot.io
CVE-2026-48764TypeBot has SSRF in HTTP request and script fetch flows via DNS rebinding bypassbaptisteArno typebot.io
CVE-2026-48763TypeBot has Arbitrary S3 Object Write in deprecated public upload endpoint via attacker-controlled filePathbaptisteArno typebot.io
CVE-2026-48762TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription HandlerbaptisteArno typebot.io
CVE-2026-48759TypeBot: Cross-Workspace Theme Template IDOR (Modification and Deletion)baptisteArno typebot.io
CVE-2026-48495TypeBot Google Sheets OAuth callback can create credentials in unauthorized workspaces and modify arbitrary typebotsbaptisteArno typebot.io
CVE-2026-48494TypeBot vulnerable to cross-typebot WhatsApp preview webhook resume via global `wa-preview-{phone}` session idsbaptisteArno typebot.io
CVE-2026-48483TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot serverbaptisteArno typebot.io
CVE-2026-47704TypeBot vulnerable to cross-typebot webhook resume via unchecked `resultId` lineage allows unauthorized control of…baptisteArno typebot.io
CVE-2026-42142TypeBot has Authorization Bypass in Google Sheets `getSheets` Endpoint that Allows Cross-Workspace Credential AccessbaptisteArno typebot.io
CVE-2026-39970TypeBot: Stored Cross-Site Scripting (XSS) via SVG File Upload On Profile Picture FormbaptisteArno typebot.io
CVE-2026-39969TypeBot: WhatsApp Webhook Endpoint Missing Signature VerificationbaptisteArno typebot.io
CVE-2026-39968TypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview EndpointbaptisteArno typebot.io
CVE-2026-39967TypeBot: Cross-Typebot Result Data Access via Missing typebotId FilterbaptisteArno typebot.io
CVE-2026-39966TypeBot: Async filter() bypasses authorization, allowing IDOR in getLinkedTypebots and leaking cross-workspace bot…baptisteArno typebot.io
CVE-2026-39965TypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code BlocksbaptisteArno typebot.io
CVE-2026-39964TypeBot: Stored XSS via javascript: URI in text bubble links — bot author executes JS on visitors' browsersbaptisteArno typebot.io
CVE-2026-34207TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request ValidationbaptisteArno typebot.io
CVE-2026-33712TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controlsbaptisteArno typebot.io
CVE-2026-28445Typebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in Builder PreviewbaptisteArno typebot.io
CVE-2026-28444Typebot: IDOR in Result Logs Endpoint Allows Cross-Workspace Data DisclosurebaptisteArno typebot.io
CVE-2025-65098Typebot Vulnerable to Credential Theft via Client-Side Script Execution and API Authorization BypassbaptisteArno typebot.io
CVE-2025-64709Typebot May Expose AWS EKS Credentials via Server Side Request Forgery in Webhook BlockbaptisteArno typebot.io
CVE-2025-64706Typebot IDOR Vulnerability: Unauthorized API Token Deletion and ExposurebaptisteArno typebot.io
34 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.