Builderio
Products
5- 3 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 0 CVEs
Recent CVEs
6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-1283 | Cri | 0.58 | 10.0 | 0.01 | Mar 8, 2023 | Code Injection in GitHub repository builderio/qwik prior to 0.21.0. | ||
| CVE-2026-92779 | Hig | 0.49 | 7.6 | 0.00 | Sep 16, 2026 | Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set helper function that processes content block bindings without validation. Attackers can craft content blocks with binding keys containing __proto__, prototype, or… | ||
| CVE-2026-82286 | Hig | 0.49 | 8.6 | 0.01 | Aug 28, 2026 | gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segments to overwrite existing files… | ||
| CVE-2026-92781 | Med | 0.41 | 6.3 | 0.00 | Sep 16, 2026 | Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. Attackers can craft preview links with __proto__ or prototype segments to… | ||
| CVE-2023-0410 | Med | 0.33 | 6.1 | 0.00 | Jan 20, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository builderio/qwik prior to 0.1.0-beta5. | ||
| CVE-2023-2307 | Med | 0.24 | 4.7 | 0.00 | Apr 26, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0. |
- risk 0.58cvss 10.0epss 0.01
Code Injection in GitHub repository builderio/qwik prior to 0.21.0.
- risk 0.49cvss 7.6epss 0.00
Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set helper function that processes content block bindings without validation. Attackers can craft content blocks with binding keys containing __proto__, prototype, or…
- risk 0.49cvss 8.6epss 0.01
gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segments to overwrite existing files…
- risk 0.41cvss 6.3epss 0.00
Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. Attackers can craft preview links with __proto__ or prototype segments to…
- risk 0.33cvss 6.1epss 0.00
Cross-site Scripting (XSS) - Generic in GitHub repository builderio/qwik prior to 0.1.0-beta5.
- risk 0.24cvss 4.7epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.