Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-66665: Type Hub <= 2.0.6: Unauthenticated File Upload Risk
CVE-2026-66665 · published 29 days ago
Summary
If left unpatched, an attacker could upload malicious files to Type Hub without needing a login. This could lead to unauthorized access or damage to your project, so it's essential to update to a secure version of Type Hub.
Original advisory text
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
Severity
10.0
Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published6 Aug 2026
Updated29 Aug 2026
First seen6 Aug 2026
Sources
CVE-2026-66665 · NVD
Monitor software like this
Free during beta