CPE
Builder.io Gen2 SDKs are vulnerable to prototype pollution in the deep-set helper function, allowing attackers to manipulate Object.prototype via unvalidated content block bindings.