Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-66665: Type Hub <= 2.0.6: Unauthenticated File Upload Risk

CVE-2026-66665 · published 29 days ago
Summary

If left unpatched, an attacker could upload malicious files to Type Hub without needing a login. This could lead to unauthorized access or damage to your project, so it's essential to update to a secure version of Type Hub.

Original advisory text
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
Severity
10.0 Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published6 Aug 2026
Updated29 Aug 2026
First seen6 Aug 2026
Sources
Monitor software like this
Free during beta