CRITICAL
Brandexponents
CVE published 2026-08-06
CVE-2026-66665
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:21.227Z and has not been modified since then. This vulnerability, CVE-2026-66665, is an unauthenticated arbitrary file upload vulnerability in Type Hub plugin versions <= 2.0.6, with a CVSS score of 10 and classified as CRITICAL. The vulnerability allows an attacker to upload arbitrary file [truncated]