Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p9x5-jp3h-96mm

Опубликовано: 02 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 9.2

Описание

Qwik vulnerable to Unauthenticated RCE via server$ Deserialization

Summary

qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any deployment where require() is available at runtime.

Impact

  • Remote Code Execution

Пакеты

Наименование

@builder.io/qwik

npm
Затронутые версииВерсия исправления

<= 1.19.0

1.19.1

EPSS

Процентиль: 96%
0.23118
Средний

9.2 Critical

CVSS4

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
nvd
27 дней назад

Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any deployment where require() is available at runtime. This vulnerability is fixed in 1.19.1.

CVSS3: 9.8
debian
27 дней назад

Qwik is a performance focused javascript framework. qwik <=1.19.0 is v ...

EPSS

Процентиль: 96%
0.23118
Средний

9.2 Critical

CVSS4

Дефекты

CWE-502