Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mgr8-fxxv-82mj

Опубликовано: 16 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.3

Описание

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. Attackers can craft preview links with proto or prototype segments to pollute Object.prototype in a visitor's browser when the SDK processes the malicious URL.

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. Attackers can craft preview links with proto or prototype segments to pollute Object.prototype in a visitor's browser when the SDK processes the malicious URL.

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 6.3
nvd
1 день назад

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. Attackers can craft preview links with __proto__ or prototype segments to pollute Object.prototype in a visitor's browser when the SDK processes the malicious URL.

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-1321