Cross-site scripting in TeamPass - #VU151631
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to a client-side output sanitization bypass in the item search-results renderer when rendering stored item labels, descriptions, or folder names. A remote attacker can store crafted markup in searchable item data to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the affected view.