CVE-2026-92779: Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via Bindings

Published Sep 16, 2026
·
Updated

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set helper function that processes content block bindings without validation. Attackers can craft content blocks with binding keys containing proto, prototype, or constructor paths to pollute Object.prototype during rendering, affecting all subsequent objects created in the process including other tenants' renders.

Affected Software

2 affected components
Builder.io Gen2 SDKs<=5.2.11
Gen2 SDKs<=0.25.13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Builder.io Gen2 SDKs to a version that resolves this vulnerability.

    Fixed in 5.2.11Patch Prototype Pollution via Bindings
  2. Upgrade

    Upgrade Builder.io Gen2 SDKs to a version that resolves this vulnerability.

    Fixed in 0.25.13Patch Prototype Pollution via Bindings

Event History

Sep 16, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using the affected Builder.io Gen2 SDK versions are exposed when they render content blocks whose bindings are processed by the vulnerable deep-set helper. The impact can extend beyond one render because pollution of Object.prototype affects subsequently created objects in the same process, including renders for other tenants.

2

What does an attacker need to exploit it?

An attacker needs to craft a content block containing binding keys with __proto__, prototype, or constructor paths. The provided data does not state any additional user interaction requirement.

3

How can teams determine whether they may be affected?

Check whether the application uses Builder.io Gen2 SDKs at or below the versions identified as affected, and whether it renders content block bindings. Review rendered or accepted content blocks for binding keys containing __proto__, prototype, or constructor path segments.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203