A critical vulnerability (CVE-2026-66665) has been identified in Type Hub versions up to 2.0.6. This issue enables unauthenticated attackers to upload arbitrary files to the affected system, potentially leading to remote code execution. The flaw arises from insufficient validation of file upload requests, allowing malicious payloads to bypass security checks. All deployments of Type Hub ≤2.0.6 are affected, exposing systems to severe risks including data compromise, service disruption, and lateral movement within networks. With a CVSS score of 10.0, this vulnerability represents an extreme priority for remediation. Immediate action is required: administrators should upgrade to Type Hub 2.0.7 or later, which includes patches to address the flaw. Until patched, disable unnecessary file upload features and implement strict input validation as temporary mitigations. Monitor for suspicious activity, including unexpected file creations or anomalous traffic patterns. This advisory underscores the importance of timely patch management to prevent exploitation of high-severity vulnerabilities.
CRITICAL
CVSS 10.0
CVE-2026-66665
2026-08-16
Critical Unauthenticated Arbitrary File Upload Vulnerability in Type Hub (CVE-2026-66665)
A critical unauthenticated arbitrary file upload vulnerability in Type Hub versions ≤2.0.6 allows remote attackers to execute malicious code. Immediate patching is required to mitigate severe risks.