← Back
CWE-200

10,878 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,878)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Aug 26, 2026
Aug 25, 2026
8.7 HIGH· v4
N/A· v3
N/A· v2
Typebot is an open-source chatbot builder. In self-hosted versions prior to 3.18.0, the server-side Send Email integration block allows arbitrary reading of local files on the server. The block builds Nodemailer attachme...Show more
Typebot is an open-source chatbot builder. In self-hosted versions prior to 3.18.0, the server-side Send Email integration block allows arbitrary reading of local files on the server. The block builds Nodemailer attachments from a typebot variable, and its parseAttachments helper returns the supplied value as a filesystem path whenever it does not start with the application's own base URL, instead of requiring an http or https URL. The Nodemailer transport is created without disableFileAccess or disableUrlAccess, both of which default to false, so an attachment specified as an absolute server path is read from the local filesystem and delivered. Because both the attachment value and the recipient list are attacker-controllable typebot variables, any registered user can publish a bot whose Send Email block attaches an absolute path such as /etc/passwd or /proc/self/environ and mails it to an address they control. This enables reading any file the server process can access, including process environment secrets such as the credential encryption key and database connection string, without administrative privileges or victim interaction. Open signup is enabled by default and the system SMTP credential is already configured, so no non-default configuration is required. This issue is fixed in version 3.18.0.Show less
1Google
1Chrome
Aug 27, 2026
Aug 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
1Google
1Chrome
Aug 27, 2026
Aug 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
1Google
1Chrome
Aug 27, 2026
Aug 25, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Information leak in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
1Google
1Chrome
Aug 31, 2026
Aug 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
1Google
1Chrome
Aug 28, 2026
Aug 25, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
1Google
1Chrome
Aug 28, 2026
Aug 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Information leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
1Google
1Chrome
Aug 28, 2026
Aug 25, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity:...Show more
Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)Show less
1Google
1Chrome
Aug 27, 2026
Aug 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Information leak in Passwords in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (Chromium security severity: Low)
1Google
1Chrome
Aug 27, 2026
Aug 25, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
1Google
1Chrome
Aug 28, 2026
Aug 25, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
1Google
1Chrome
Aug 31, 2026
Aug 25, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium security...Show more
Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)Show less
1Google
1Chrome
Aug 31, 2026
Aug 25, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Information leak in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)
1Google
1Chrome
Aug 31, 2026
Aug 25, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
1Google
1Chrome
Aug 27, 2026
Aug 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Information leak in XR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
1Google
1Chrome
Aug 27, 2026
Aug 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Information leak in Intents in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
1Google
1Chrome
Aug 27, 2026
Aug 25, 2026
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)
1Google
1Chrome
Aug 28, 2026
Aug 25, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Information leak in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
1Google
1Chrome
Aug 31, 2026
Aug 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Information leak in Geolocation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium...Show more
Information leak in Geolocation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)Show less
1Google
1Chrome
Aug 28, 2026
Aug 25, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity:...Show more
Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)Show less