Cross-site scripting in TeamPass - #VU151633
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper encoding for a JSON string context in the background-task log table renderer when rendering stored display values. A remote attacker can store crafted markup in a background-task display value to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the affected view.