OffSeq’s Post

🚨 A CRITICAL SSRF flaw (CVE-2025-64709, CVSS 9.6) in Typebot (<3.13.1) allows authenticated users to inject requests, extract AWS EKS IAM credentials, and potentially compromise entire Kubernetes clusters. Immediate upgrade to v3.13.1+ is essential to prevent cloud takeover. Action steps: Patch Typebot, restrict webhook block access, enforce AWS IAM least privilege, and monitor for unusual outbound requests. This vulnerability threatens both confidentiality and integrity—especially for organizations with strict compliance needs. https://lnkd.in/d6fXX4XN #OffSeq #CloudSecurity #AWS #Kubernetes #SSRF

  • Critical threat detected

To view or add a comment, sign in

Explore content categories