Cross-site scripting in TeamPass - #VU151642
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper output encoding in the item-deleted WebSocket toast renderer when handling item-deleted events. A remote attacker can cause a crafted item label to be rendered in a WebSocket toast to execute arbitrary JavaScript in another user's browser.
User interaction is required to receive the affected event.