GHSA-6m7c-xfhp-p9fh
HIGHCVE-2026-28445The rating block's custom icon feature accepts arbitrary HTML/SVG via the customIcon.svg field and renders it using Solid's innerHTML directive without any sanitization. When a malicious typebot is imported or crafted by a workspace collaborator, the payload executes in the builder's DOM context (builder.typebot.io), bypassing the isUnsafe Web Worker sandbox that protects Script blocks during prev
- Affected
- >=0, <0.10.1, < 0.10.1
- Fixed in
- 0.10.1
- Weakness
- CWE-79
- Published
- 2026-05-26
- Source
- osv