Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Builderio
Builderio sdk-angular Builderio sdk-qwik Builderio sdk-react Builderio sdk-react-nextjs Builderio sdk-solid Builderio sdk-svelte Builderio sdk-vue |
|
| Vendors & Products |
Builderio
Builderio sdk-angular Builderio sdk-qwik Builderio sdk-react Builderio sdk-react-nextjs Builderio sdk-solid Builderio sdk-svelte Builderio sdk-vue |
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. Attackers can craft preview links with __proto__ or prototype segments to pollute Object.prototype in a visitor's browser when the SDK processes the malicious URL. | |
| Title | Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via builder.userAttributes | |
| Weaknesses | CWE-1321 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:32:38.923Z
Reserved: 2026-09-16T19:22:53.825Z
Link: CVE-2026-92781
No data.
Status : Received
Published: 2026-09-16T21:17:27.130
Modified: 2026-09-16T21:17:27.130
Link: CVE-2026-92781
No data.
OpenCVE Enrichment
Updated: 2026-09-18T20:03:20Z
-
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')