Prototype Pollution Vulnerability in Builder.io Gen2 SDKs
CVE-2026-92781

5.3MEDIUM

What is CVE-2026-92781?

The Builder.io Gen2 SDKs, up to versions 5.2.11 and 0.25.13, are susceptible to a prototype pollution vulnerability. This issue arises from the unflatten helper function that processes builder.userAttributes query parameters without adequate prototype guards. Attackers can exploit this flaw by crafting preview links that include proto or prototype segments, leading to the pollution of Object.prototype in a visitor's web browser. This vulnerability poses significant security risks, potentially allowing attackers to manipulate the object's properties or methods, thereby compromising the integrity of web applications that utilize the affected SDKs.

Affected Version(s)

@builder.io/sdk-angular 0 <= 0.25.13

@builder.io/sdk-qwik 0 <= 0.25.13

@builder.io/sdk-react 0 <= 5.2.11

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.