Vulnerabilidades en baptisteArno
31 resultadosAnálisis Vexday
O fornecedor baptisteArno apresenta 19 vulnerabilidades catalogadas, com 15 publicadas nos últimos 90 dias, indicando atividade recente significativa na superfície de exposição. Embora nenhuma vulnerabilidade esteja sob ataque ativo no momento, 3 são classificadas como críticas e a fraqueza dominante (CWE-639: autorização inadequada) representa um vetor de risco estrutural que demanda revisão de controles de acesso. O volume concentrado em janela recente sugere acompanhamento contínuo para identificar possíveis exploração futura.
CVE-2024-30264HIGHtypebot.io: `GHSL-2024-040`EPSS 0.8%CVE-2026-47704HIGHTypeBot vulnerable to cross-typebot webhook resume via unchecked `resultId` lineage allows unauthorized control of another bot's waiting sessionEPSS 0.5%CVE-2026-47705CRITICALTypeBot vulnerable to CSV injection in result exportEPSS 0.4%CVE-2025-64709CRITICALTypebot May Expose AWS EKS Credentials via Server Side Request Forgery in Webhook BlockEPSS 0.4%CVE-2026-33712CRITICALTypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controlsEPSS 0.3%CVE-2026-48494HIGHTypeBot vulnerable to cross-typebot WhatsApp preview webhook resume via global `wa-preview-{phone}` session idsEPSS 0.3%CVE-2026-48483MEDIUMTypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot serverEPSS 0.3%CVE-2026-49213HIGHTypeBot: SSRF protection bypass via IPv6 unspecified address in Typebot HTTP request executionEPSS 0.3%CVE-2026-28444MEDIUMTypebot: IDOR in Result Logs Endpoint Allows Cross-Workspace Data DisclosureEPSS 0.3%CVE-2026-48767HIGHGoogle Sheets OAuth access token disclosure to guest members via getAccessTokenEPSS 0.3%CVE-2026-48766HIGHTypeBot vulnerable to OpenAI API key exfiltration in listModels via attacker-controlled baseUrlEPSS 0.3%CVE-2026-48763HIGHTypeBot has Arbitrary S3 Object Write in deprecated public upload endpoint via attacker-controlled filePathEPSS 0.3%CVE-2025-65098HIGHTypebot Vulnerable to Credential Theft via Client-Side Script Execution and API Authorization BypassEPSS 0.3%CVE-2026-39970HIGHTypeBot: Stored Cross-Site Scripting (XSS) via SVG File Upload On Profile Picture FormEPSS 0.3%CVE-2026-48764HIGHTypeBot has SSRF in HTTP request and script fetch flows via DNS rebinding bypassEPSS 0.3%CVE-2026-39968HIGHTypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview EndpointEPSS 0.3%CVE-2026-42142HIGHTypeBot has Authorization Bypass in Google Sheets `getSheets` Endpoint that Allows Cross-Workspace Credential AccessEPSS 0.3%CVE-2026-48768CRITICALTypeBot: Unauthenticated arbitrary s3 object write in generate-upload-url via unsanitized fileNameEPSS 0.3%CVE-2026-28445HIGHTypebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in Builder PreviewEPSS 0.3%CVE-2026-39966MEDIUMTypeBot: Async filter() bypasses authorization, allowing IDOR in getLinkedTypebots and leaking cross-workspace bot definitionsEPSS 0.3%