Cross-site scripting in TeamPass - #VU151645
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper neutralization of JavaScript line terminators in the items page script when rendering the session language in a JavaScript comment. A remote attacker can store a crafted session language value to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the items page.