Cross-site scripting in TeamPass - #VU151644
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper output encoding in the item list icon renderer when rendering API-controlled icon values in an HTML attribute. A remote attacker can supply a crafted icon value through the API to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the affected view.