Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vm6g-8r4h-22x8

Опубликовано: 03 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Qwik City CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)

Summary

A typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type headers.

Impact

An attacker can bypass Qwik City’s Origin-based CSRF protections and perform forged form submissions, potentially causing unauthorized state changes.

Пакеты

Наименование

@builder.io/qwik-city

npm
Затронутые версииВерсия исправления

< 1.12.0

1.12.0

EPSS

Процентиль: 0%
0.00005
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 5.9
nvd
3 дня назад

Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type headers. This issue has been patched in version 1.12.0.

CVSS3: 5.9
debian
3 дня назад

Qwik is a performance focused javascript framework. Prior to version 1 ...

EPSS

Процентиль: 0%
0.00005
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-352