Cross-site scripting in TeamPass - #VU151629
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in another user's browser session.
The vulnerability exists due to improper output encoding in client-side rendering code when rendering user-controlled item labels, folder titles, directory attributes, and identity fields. A remote privileged user can store crafted values to execute arbitrary JavaScript in another user's browser session.
User interaction is required to open an affected screen.