Prototype Pollution Vulnerability in Builder.io Gen2 SDKs
CVE-2026-92781
What is CVE-2026-92781?
The Builder.io Gen2 SDKs, up to versions 5.2.11 and 0.25.13, are susceptible to a prototype pollution vulnerability. This issue arises from the unflatten helper function that processes builder.userAttributes query parameters without adequate prototype guards. Attackers can exploit this flaw by crafting preview links that include proto or prototype segments, leading to the pollution of Object.prototype in a visitor's web browser. This vulnerability poses significant security risks, potentially allowing attackers to manipulate the object's properties or methods, thereby compromising the integrity of web applications that utilize the affected SDKs.
Affected Version(s)
@builder.io/sdk-angular 0 <= 0.25.13
@builder.io/sdk-qwik 0 <= 0.25.13
@builder.io/sdk-react 0 <= 5.2.11
