{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/gen2-sdks--0.25.13/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:builder:gen2_sdks:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.6,"id":"CVE-2026-92779"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Gen2 SDKs (\u003c= 5.2.11)","Gen2 SDKs (\u003c= 0.25.13)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","javascript"],"_cs_type":"advisory","_cs_vendors":["Builder.io"],"content_html":"\u003cp\u003eBuilder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability residing within the deep-set helper function. The vulnerability arises from the failure to properly validate content block bindings before processing. An attacker can craft malicious content blocks that include specific keys such as \u003cstrong\u003eproto\u003c/strong\u003e, prototype, or constructor. When these blocks are rendered by the application, the vulnerable deep-set function inadvertently merges these keys into the global Object.prototype. Because this pollutes the prototype of all objects within the JavaScript runtime process, it can influence the behavior of unrelated objects, potentially leading to cross-tenant data corruption or systemic logic disruption within the rendering engine. This vulnerability is particularly critical for multi-tenant environments where shared instances may process untrusted content from multiple users.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the modification of object behavior application-wide. In multi-tenant environments, this could lead to cross-tenant information disclosure or cross-site scripting by altering the properties of objects relied upon by other users or administrative components. The severity is high due to the potential for impacting subsequent renders and affecting the core execution logic of the application process.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Builder.io Gen2 SDKs to versions 5.2.12 and 0.25.14 or later to address the vulnerable deep-set helper function.\u003c/li\u003e\n\u003cli\u003eAudit applications using the SDK for any custom deep-merging or property-setting logic that might mirror the vulnerability in CVE-2026-92779.\u003c/li\u003e\n\u003cli\u003eIn multi-tenant environments, ensure proper sandboxing or process isolation between different content block rendering tasks to minimize the blast radius of prototype pollution.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T21:56:01Z","date_published":"2026-09-16T21:56:01Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-92779-prototype-pollution/","summary":"Builder.io Gen2 SDKs are vulnerable to prototype pollution in the deep-set helper function, allowing attackers to manipulate Object.prototype via unvalidated content block bindings.","title":"Prototype Pollution in Builder.io Gen2 SDKs","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-92779-prototype-pollution/"}],"language":"en","title":"CraftedSignal Threat Feed - Gen2 SDKs (\u003c= 0.25.13)","version":"https://jsonfeed.org/version/1.1"}