Cross-site scripting in TeamPass - #VU151659
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the search results expand card when rendering stored item label, login, or URL values. A remote user can store a crafted item field value to execute arbitrary JavaScript in a victim's browser.
Exploitation requires a victim with read access to the affected folder to expand a matching search result.