Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

baptisteArno — Vulnerabilities & Security Advisories 34

Browse all 34 CVE security advisories affecting baptisteArno. AI-powered Chinese analysis, POCs, and references for each vulnerability.

BaptisteArno is a security researcher focused on identifying vulnerabilities in web applications and software systems, with four CVEs primarily related to remote code execution and cross-site scripting flaws. Their work often centers on uncovering authentication bypasses and privilege escalation issues in widely-used platforms. While no major public security incidents are directly attributed to this researcher, their contributions highlight persistent weaknesses in input validation and access control mechanisms. BaptisteArno's findings typically demonstrate how improper sanitization of user inputs can lead to comprehensive system compromises, emphasizing the ongoing need for robust security practices in development lifecycles.

Top products by baptisteArno: typebot.io
CVE ID Title CVSS Severity Published
CVE-2026-62865 TypeBot: Arbitrary server file read via Send Email block attachment path — typebot.io CWE-200 8.7 High 2026-08-25
CVE-2026-62861 TypeBot: Cross-tenant custom-domain removal via unbound `name` in handleDeleteCustomDomain — typebot.io CWE-639 6.4 Medium 2026-08-25
CVE-2026-62862 TypeBot: Account takeover via brute-forceable 6-digit magic-link code — typebot.io CWE-307 9.1 Critical 2026-08-25
CVE-2026-48763 TypeBot has Arbitrary S3 Object Write in deprecated public upload endpoint via attacker-controlled filePath — typebot.io CWE-862 8.2 High 2026-08-11
CVE-2026-48762 TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription Handler — typebot.io CWE-918 5.4 Medium 2026-08-11
CVE-2026-48765 TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials via missing object binding — typebot.io CWE-639 9.9 Critical 2026-08-11
CVE-2026-47705 TypeBot vulnerable to CSV injection in result export — typebot.io CWE-1236 9.6 Critical 2026-08-11
CVE-2026-48767 Google Sheets OAuth access token disclosure to guest members via getAccessToken — typebot.io CWE-200 7.6 High 2026-08-11
CVE-2026-48494 TypeBot vulnerable to cross-typebot WhatsApp preview webhook resume via global `wa-preview-{phone}` session ids — typebot.io CWE-639 7.1 High 2026-08-11
CVE-2026-47704 TypeBot vulnerable to cross-typebot webhook resume via unchecked `resultId` lineage allows unauthorized control of another bot's waiting session — typebot.io CWE-639 7.1 High 2026-08-11
CVE-2026-48483 TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot server — typebot.io CWE-918 5.4 Medium 2026-08-11
CVE-2026-48495 TypeBot Google Sheets OAuth callback can create credentials in unauthorized workspaces and modify arbitrary typebots — typebot.io CWE-862 7.1 High 2026-08-11
CVE-2026-48766 TypeBot vulnerable to OpenAI API key exfiltration in listModels via attacker-controlled baseUrl — typebot.io CWE-200 7.6 High 2026-08-11
CVE-2026-42142 TypeBot has Authorization Bypass in Google Sheets `getSheets` Endpoint that Allows Cross-Workspace Credential Access — typebot.io CWE-862 7.1 High 2026-08-11
CVE-2026-47702 TypeBot API tokens stored in plaintext — typebot.io CWE-312 9.1 Critical 2026-08-11
CVE-2026-49213 TypeBot: SSRF protection bypass via IPv6 unspecified address in Typebot HTTP request execution — typebot.io CWE-918 8.1 High 2026-07-10
CVE-2026-48764 TypeBot has SSRF in HTTP request and script fetch flows via DNS rebinding bypass — typebot.io CWE-918 8.2 High 2026-06-17
CVE-2026-48768 TypeBot: Unauthenticated arbitrary s3 object write in generate-upload-url via unsanitized fileName — typebot.io CWE-22 9.3 Critical 2026-06-17
CVE-2026-48759 TypeBot: Cross-Workspace Theme Template IDOR (Modification and Deletion) — typebot.io CWE-639 7.1 High 2026-06-17
CVE-2026-39969 TypeBot: WhatsApp Webhook Endpoint Missing Signature Verification — typebot.io CWE-287 6.5 Medium 2026-05-22
CVE-2026-39967 TypeBot: Cross-Typebot Result Data Access via Missing typebotId Filter — typebot.io CWE-639 3.1 Low 2026-05-22
CVE-2026-39968 TypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview Endpoint — typebot.io CWE-284 7.1 High 2026-05-22
CVE-2026-39966 TypeBot: Async filter() bypasses authorization, allowing IDOR in getLinkedTypebots and leaking cross-workspace bot definitions — typebot.io CWE-863 6.5 Medium 2026-05-22
CVE-2026-39970 TypeBot: Stored Cross-Site Scripting (XSS) via SVG File Upload On Profile Picture Form — typebot.io CWE-79 - - 2026-05-22
CVE-2026-39965 TypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code Blocks — typebot.io CWE-918 7.7 High 2026-05-22
CVE-2026-39964 TypeBot: Stored XSS via javascript: URI in text bubble links — bot author executes JS on visitors' browsers — typebot.io CWE-79 5.4 Medium 2026-05-22
CVE-2026-34207 TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request Validation — typebot.io CWE-20 7.6 High 2026-05-22
CVE-2026-33712 TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls — typebot.io CWE-862 10.0 Critical 2026-05-22
CVE-2026-28445 Typebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in Builder Preview — typebot.io CWE-79 8.7 High 2026-05-22
CVE-2026-28444 Typebot: IDOR in Result Logs Endpoint Allows Cross-Workspace Data Disclosure — typebot.io CWE-639 6.5 Medium 2026-05-22

This page lists every published CVE security advisory associated with baptisteArno. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.