PT-2025-28958 · Builder.Io · @Builder.Io/Qwik-City

Finalgamer

·

Published

2025-07-09

·

Updated

2025-07-11

·

CVE-2025-53620

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions: @builder.io/qwik-city versions prior to 1.13.0
Description: The @builder.io/qwik-city meta-framework for Qwik is susceptible to an issue where improper handling of invalid qfunc during the execution of a Qwik Server Action QRL can lead to a Node.js process exit. This occurs because the server does not manage errors thrown when an invalid qfunc is encountered.
Recommendations: Update to version 1.13.0 or later.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

BDU:2025-14615
CVE-2025-53620
GHSA-QR9H-J6XG-2J72

Affected Products

@Builder.Io/Qwik-City