Cross-site scripting in TeamPass - #VU140792
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the One-Time View page (`app/core/otv.php`) when rendering a stored item URL field into HTML. A remote user can create an item with a crafted URL and send an OTV link to a victim to execute arbitrary script in a victim's browser.
User interaction is required to open the crafted OTV link, and the feature may be shared with recipients who do not have a TeamPass account.