CVE-2026-92779
YüksekTeknik Veri (Otomatik)
- CVSS Skoru
- 7.6
- EPSS
- —
- CWE
- CWE-1321
- KEV Durumu
- Hayır
Builder.io Gen2 SDK'ları 5.2.11 ve 0.25.13 sürümlerine kadar, içerik bloğu bağlamalarını doğrulama olmadan işleyen deep-set yardımcı fonksiyonunda bir prototype kirlenmesi zafiyeti içerir. Saldırganlar, __proto__, prototype veya constructor yollarını içeren bağlama anahtarlarına sahip içerik blokları oluşturabilir ve işleme sırasında Object.prototype'i kirletebilir, bu da oluşturulan tüm sonraki nesneleri, diğer kiracıların işlemlerini de etkiler.
Orijinal açıklama (İngilizce)
Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set helper function that processes content block bindings without validation. Attackers can craft content blocks with binding keys containing __proto__, prototype, or constructor paths to pollute Object.prototype during rendering, affecting all subsequent objects created in the process including other tenants' renders.
Referanslar
- https://github.com/BuilderIO/builder
- https://github.com/BuilderIO/builder/blob/main/packages/sdks/src/functions/get-processed-block.ts#L84-L93
- https://github.com/BuilderIO/builder/blob/main/packages/sdks/src/functions/set.ts#L7-L26
- https://github.com/BuilderIO/builder/issues/4823
- https://www.vulncheck.com/advisories/builder-io-gen2-sdks-through-5.2.11-prototype-pollution-via-bindings
Bu CVE için henüz editoryal inceleme yapılmadı. Sadece otomatik teknik veri gösteriliyor.
