PT-2026-6275 · Builder.Io+1 · @Builder.Io/Qwik-City+1
Yueyuel
·
Publicado
2026-02-03
·
Atualizado
2026-02-04
·
CVE-2026-25150
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Qwik versions prior to 1.19.0
Description
Qwik is a performance focused javascript framework. A prototype pollution issue exists in the
formToObj() function within the @builder.io/qwik-city middleware. The function processes form field names using dot notation, but does not sanitize dangerous property names like proto, constructor, and prototype. This allows unauthenticated attackers to pollute Object.prototype by sending crafted HTTP POST requests, potentially leading to privilege escalation, authentication bypass, or denial of service.Recommendations
Update to version 1.19.0 or later.
Exploit
Correção
LPE
DoS
Prototype Pollution
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
@Builder.Io/Qwik-City
Qwik