Cross-site scripting in TeamPass - #VU140728
Published: August 2, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in a victim's browser session.
The vulnerability exists due to improper neutralization of input during web page generation in the recycle-bin frontend renderer when rendering deleted item labels returned by the recycle-bin listing API. A remote user can create and delete an item with a crafted HTML label through the REST API to execute arbitrary script in a victim's browser session.
User interaction is required, and exploitation requires REST API item create/delete permissions and a victim with access to the Utilities deletion page.