Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Builderio
Builderio sdk-angular Builderio sdk-qwik Builderio sdk-react Builderio sdk-react-nextjs Builderio sdk-solid Builderio sdk-svelte Builderio sdk-vue |
|
| Vendors & Products |
Builderio
Builderio sdk-angular Builderio sdk-qwik Builderio sdk-react Builderio sdk-react-nextjs Builderio sdk-solid Builderio sdk-svelte Builderio sdk-vue |
Thu, 17 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set helper function that processes content block bindings without validation. Attackers can craft content blocks with binding keys containing __proto__, prototype, or constructor paths to pollute Object.prototype during rendering, affecting all subsequent objects created in the process including other tenants' renders. | |
| Title | Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via Bindings | |
| Weaknesses | CWE-1321 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T19:25:04.694Z
Reserved: 2026-09-16T19:22:53.082Z
Link: CVE-2026-92779
Updated: 2026-09-17T19:16:57.590Z
Status : Received
Published: 2026-09-16T21:17:26.827
Modified: 2026-09-17T20:18:57.833
Link: CVE-2026-92779
No data.
OpenCVE Enrichment
Updated: 2026-09-18T20:03:25Z
-
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')