Cross-site scripting in TeamPass - #VU151660
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the item login field renderer, #card-item-login, when a non-administrator opens a poisoned item detail view. A remote user can create or edit an item with a crafted login value to execute arbitrary JavaScript in another user's browser.
The login value is rendered for non-administrators with read access to the relevant folder.