Impact
Builder.io Gen2 SDKs up to versions 5.2.11 and 0.25.13 contain a prototype pollution flaw in a deep‑set helper that processes content block bindings without validation. An attacker can craft bindings whose keys include __proto__, prototype, or constructor paths, causing Object.prototype to be polluted during rendering. The altered prototype persists for all subsequently created objects, potentially corrupting data and behavior for all tenants that render content blocks processed by the affected SDK.
Affected Systems
The vulnerability affects Builder.io Gen2 SDKs for Angular, Qwik, React, React‑Nextjs, Solid, Svelte, and Vue. Affected hosts include packages @builder.io/sdk-angular, @builder.io/sdk-qwik, @builder.io/sdk-react, @builder.io/sdk-react-nextjs, @builder.io/sdk-solid, @builder.io/sdk-svelte, and @builder.io/sdk-vue, with vulnerable versions up to 5.2.11 for the main SDK and 0.25.13 for the auxiliary modules.
Risk and Exploitability
The CVSS score of 7.2 indicates a moderate to high risk, while the EPSS score of less than 1 % suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation occurs when a malicious or compromised content block is rendered by the SDK; the attacker does not need elevated privileges beyond the ability to supply content blocks. Successful exploitation can lead to unintended modifications of prototype‐based values, which can affect all user‑generated content processed on the same server or platform.
OpenCVE Enrichment