Impact
The vulnerability is a prototype pollution flaw in the unflatten helper of Builder.io Gen2 SDKs. The helper processes builder.userAttributes query parameters without guarding against prototype keys, allowing attackers to craft preview links that contain __proto__ or prototype segments. When the SDK handles such a malicious URL in a visitor’s browser, Object.prototype is polluted, which can alter the behavior of any code that relies on built‑in object prototypes. This manipulation can lead to unintended logic changes or the execution of malicious scripts if the polluted property is subsequently leveraged by the application.
Affected Systems
The affected products are the Builder.io Gen2 SDKs for Angular, Qwik, React, React‑NextJS, Solid, Svelte, and Vue. Versions through 5.2.11 for most SDKs and 0.25.13 for the remaining packages are vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. The EPSS score is less than 1%, signifying a very low exploitation probability in the current landscape. The vulnerability is not listed in CISA KEV. Attackers employ a crafted preview link that the SDK parses client‑side; if a user visits the link in a browser that loads the SDK, Object.prototype becomes polluted. The risk is restricted to browsers that execute the SDK when loading such links, but it can affect all visitors who open malicious preview URLs crafted by the attacker.
OpenCVE Enrichment