Description
Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. Attackers can craft preview links with __proto__ or prototype segments to pollute Object.prototype in a visitor's browser when the SDK processes the malicious URL.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Prototype Pollution
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a prototype pollution flaw in the unflatten helper of Builder.io Gen2 SDKs. The helper processes builder.userAttributes query parameters without guarding against prototype keys, allowing attackers to craft preview links that contain __proto__ or prototype segments. When the SDK handles such a malicious URL in a visitor’s browser, Object.prototype is polluted, which can alter the behavior of any code that relies on built‑in object prototypes. This manipulation can lead to unintended logic changes or the execution of malicious scripts if the polluted property is subsequently leveraged by the application.

Affected Systems

The affected products are the Builder.io Gen2 SDKs for Angular, Qwik, React, React‑NextJS, Solid, Svelte, and Vue. Versions through 5.2.11 for most SDKs and 0.25.13 for the remaining packages are vulnerable.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity. The EPSS score is less than 1%, signifying a very low exploitation probability in the current landscape. The vulnerability is not listed in CISA KEV. Attackers employ a crafted preview link that the SDK parses client‑side; if a user visits the link in a browser that loads the SDK, Object.prototype becomes polluted. The risk is restricted to browsers that execute the SDK when loading such links, but it can affect all visitors who open malicious preview URLs crafted by the attacker.

Generated by OpenCVE AI on September 18, 2026 at 06:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a patched BuilderIO SDK version that adds prototype guards in the unflatten helper (e.g., 5.2.12 or later, 0.25.14 or later).
  • If no immediate patch is available, sanitize builder.userAttributes query parameters on the client side before passing them to the SDK, stripping any __proto__ or prototype keys.
  • Deploy a strict Content Security Policy that limits inline script execution to mitigate potential XSS resulting from polluted prototypes.

Generated by OpenCVE AI on September 18, 2026 at 06:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Builderio
Builderio sdk-angular
Builderio sdk-qwik
Builderio sdk-react
Builderio sdk-react-nextjs
Builderio sdk-solid
Builderio sdk-svelte
Builderio sdk-vue
Vendors & Products Builderio
Builderio sdk-angular
Builderio sdk-qwik
Builderio sdk-react
Builderio sdk-react-nextjs
Builderio sdk-solid
Builderio sdk-svelte
Builderio sdk-vue

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. Attackers can craft preview links with __proto__ or prototype segments to pollute Object.prototype in a visitor's browser when the SDK processes the malicious URL.
Title Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via builder.userAttributes
Weaknesses CWE-1321
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Builderio Sdk-angular Sdk-qwik Sdk-react Sdk-react-nextjs Sdk-solid Sdk-svelte Sdk-vue
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T15:50:13.299Z

Reserved: 2026-09-16T19:22:53.825Z

Link: CVE-2026-92781

cve-icon Vulnrichment

Updated: 2026-09-21T15:49:50.725Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:27.130

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-92781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:03:20Z

Weaknesses
  • CWE-1321

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')