Blind Cross-Site Scripting Vulnerability in Teampass by Teampass
CVE-2026-3106
9.3CRITICAL
What is CVE-2026-3106?
A Blind Cross-Site Scripting vulnerability exists in Teampass, specifically in the password manager login functionality. When users attempt to log in and fail, the application fails to adequately sanitize the information in the username field. This oversight allows arbitrary JavaScript to be executed in the administrator's browser when accessing failed login attempts. This vulnerability emphasizes the need for robust input validation and proper encoding practices in web applications to prevent potential exploitation.
Affected Version(s)
Teampass 0 <= 3.1.5.16
