Vulnerabilidades em baptisteArno
18 resultadosCVE-2024-30264HIGHtypebot.io: `GHSL-2024-040`EPSS 0.8%CVE-2026-33712CRITICALTypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controlsEPSS 0.3%CVE-2025-64709CRITICALTypebot May Expose AWS EKS Credentials via Server Side Request Forgery in Webhook BlockEPSS 0.3%CVE-2026-28444MEDIUMTypebot: IDOR in Result Logs Endpoint Allows Cross-Workspace Data DisclosureEPSS 0.3%CVE-2025-65098HIGHTypebot Vulnerable to Credential Theft via Client-Side Script Execution and API Authorization BypassEPSS 0.3%CVE-2026-39970HIGHTypeBot: Stored Cross-Site Scripting (XSS) via SVG File Upload On Profile Picture FormEPSS 0.3%CVE-2026-48764HIGHTypeBot has SSRF in HTTP request and script fetch flows via DNS rebinding bypassEPSS 0.3%CVE-2026-39968HIGHTypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview EndpointEPSS 0.3%CVE-2026-48768CRITICALTypeBot: Unauthenticated arbitrary s3 object write in generate-upload-url via unsanitized fileNameEPSS 0.3%CVE-2026-28445HIGHTypebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in Builder PreviewEPSS 0.3%CVE-2026-39966MEDIUMTypeBot: Async filter() bypasses authorization, allowing IDOR in getLinkedTypebots and leaking cross-workspace bot definitionsEPSS 0.3%CVE-2026-39964MEDIUMTypeBot: Stored XSS via javascript: URI in text bubble links — bot author executes JS on visitors' browsersEPSS 0.2%CVE-2026-39965HIGHTypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code BlocksEPSS 0.2%CVE-2026-34207HIGHTypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request ValidationEPSS 0.2%CVE-2025-64706MEDIUMTypebot IDOR Vulnerability: Unauthorized API Token Deletion and ExposureEPSS 0.2%CVE-2026-48759HIGHTypeBot: Cross-Workspace Theme Template IDOR (Modification and Deletion)EPSS 0.2%CVE-2026-39967LOWTypeBot: Cross-Typebot Result Data Access via Missing typebotId FilterEPSS 0.2%CVE-2026-39969MEDIUMTypeBot: WhatsApp Webhook Endpoint Missing Signature VerificationEPSS 0.1%