Cross-site scripting in TeamPass - #VU151631

 

Cross-site scripting in TeamPass - #VU151631

Published: September 22, 2026


Vulnerability identifier: #VU151631
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.

The vulnerability exists due to a client-side output sanitization bypass in the item search-results renderer when rendering stored item labels, descriptions, or folder names. A remote attacker can store crafted markup in searchable item data to execute arbitrary JavaScript in another user's browser.

User interaction is required to open the affected view.


Affected software

TeamPass

Remediation

Install security update from vendor's website.

TeamPass - update to 3.2.0.3

External References

Related Security Bulletins