Cross-site scripting in TeamPass - #VU151629

 

Cross-site scripting in TeamPass - #VU151629

Published: September 22, 2026


Vulnerability identifier: #VU151629
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in another user's browser session.

The vulnerability exists due to improper output encoding in client-side rendering code when rendering user-controlled item labels, folder titles, directory attributes, and identity fields. A remote privileged user can store crafted values to execute arbitrary JavaScript in another user's browser session.

User interaction is required to open an affected screen.


Affected software

TeamPass

Remediation

Install security update from vendor's website.

TeamPass - update to 3.2.1.6

External References

Related Security Bulletins