Prototype Pollution in Builder.io Gen2 SDK
CVE-2026-92779
7.2HIGH
What is CVE-2026-92779?
The Builder.io Gen2 SDKs up to version 5.2.11 and 0.25.13 are susceptible to a prototype pollution exploit due to inadequate validation in the deep-set helper function. This vulnerability allows attackers to create content blocks containing binding keys like proto, prototype, or constructor. When these contents are processed, they can inadvertently modify Object.prototype, impacting all objects created thereafter. This can potentially lead to unauthorized access and manipulation of rendered content across all tenant environments, posing significant risks to application integrity and data security.
Affected Version(s)
@builder.io/sdk-angular 0 <= 0.25.13
@builder.io/sdk-qwik 0 <= 0.25.13
@builder.io/sdk-react 0 <= 5.2.11
