CVE-2026-92781
OrtaTeknik Veri (Otomatik)
- CVSS Skoru
- 6.3
- EPSS
- —
- CWE
- CWE-1321
- KEV Durumu
- Hayır
Builder.io Gen2 SDK'leri 5.2.11 ve 0.25.13 sürümlerine kadar, prototype korumaları olmadan builder.userAttributes sorgu parametrelerini işleyen unflatten yardımcı fonksiyonunda bir prototype kirlenmesi zafiyeti içerir. Saldırganlar, SDK'nin kötü niyetli URL'yi işlediğinde bir ziyaretçinin tarayıcısında Object.prototype'ü kirletmek için __proto__ veya prototype parçaları içeren ön izleme bağlantıları oluşturabilir.
Orijinal açıklama (İngilizce)
Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. Attackers can craft preview links with __proto__ or prototype segments to pollute Object.prototype in a visitor's browser when the SDK processes the malicious URL.
Referanslar
- https://github.com/BuilderIO/builder
- https://github.com/BuilderIO/builder/blob/main/packages/sdks/src/functions/get-content/generate-content-url.ts
- https://github.com/BuilderIO/builder/blob/main/packages/sdks/src/helpers/flatten.ts#L60-L76
- https://github.com/BuilderIO/builder/issues/4824
- https://www.vulncheck.com/advisories/builder-io-gen2-sdks-through-5.2.11-prototype-pollution-via-builder-userattributes
Bu CVE için henüz editoryal inceleme yapılmadı. Sadece otomatik teknik veri gösteriliyor.
