PT-2026-6275 · Builder.Io+1 · @Builder.Io/Qwik-City+1

Yueyuel

·

Publicado

2026-02-03

·

Atualizado

2026-02-04

·

CVE-2026-25150

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Qwik versions prior to 1.19.0
Description Qwik is a performance focused javascript framework. A prototype pollution issue exists in the formToObj() function within the @builder.io/qwik-city middleware. The function processes form field names using dot notation, but does not sanitize dangerous property names like proto, constructor, and prototype. This allows unauthenticated attackers to pollute Object.prototype by sending crafted HTTP POST requests, potentially leading to privilege escalation, authentication bypass, or denial of service.
Recommendations Update to version 1.19.0 or later.

Exploit

Correção

LPE

DoS

Prototype Pollution

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25150
GHSA-XQG6-98CW-GXHQ

Produtos afetados

@Builder.Io/Qwik-City
Qwik