VYPR
Vendor

Builderio

Products
5
CVEs
6
Across products
7
Status
Private

Products

5

Recent CVEs

6
  • CVE-2023-1283CriMar 8, 2023
    risk 0.58cvss 10.0epss 0.01

    Code Injection in GitHub repository builderio/qwik prior to 0.21.0.

  • CVE-2026-92779HigSep 16, 2026
    risk 0.49cvss 7.6epss 0.00

    Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set helper function that processes content block bindings without validation. Attackers can craft content blocks with binding keys containing __proto__, prototype, or…

  • CVE-2026-82286HigAug 28, 2026
    risk 0.49cvss 8.6epss 0.01

    gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segments to overwrite existing files…

  • CVE-2026-92781MedSep 16, 2026
    risk 0.41cvss 6.3epss 0.00

    Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. Attackers can craft preview links with __proto__ or prototype segments to…

  • CVE-2023-0410MedJan 20, 2023
    risk 0.33cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Generic in GitHub repository builderio/qwik prior to 0.1.0-beta5.

  • CVE-2023-2307MedApr 26, 2023
    risk 0.24cvss 4.7epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.