Prototype Pollution in Builder.io Gen2 SDK
CVE-2026-92779

7.2HIGH

What is CVE-2026-92779?

The Builder.io Gen2 SDKs up to version 5.2.11 and 0.25.13 are susceptible to a prototype pollution exploit due to inadequate validation in the deep-set helper function. This vulnerability allows attackers to create content blocks containing binding keys like proto, prototype, or constructor. When these contents are processed, they can inadvertently modify Object.prototype, impacting all objects created thereafter. This can potentially lead to unauthorized access and manipulation of rendered content across all tenant environments, posing significant risks to application integrity and data security.

Affected Version(s)

@builder.io/sdk-angular 0 <= 0.25.13

@builder.io/sdk-qwik 0 <= 0.25.13

@builder.io/sdk-react 0 <= 5.2.11

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.