Cross-site scripting in TeamPass - #VU151658
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in another user's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the loadItemHistory item-history rendering of value.detail when processing previous item-field values in audit-log history entries. A remote user can store a crafted item field value and later edit the field to execute arbitrary script in another user's browser.
User interaction is required to open the affected item.