PT-2025-28958 · Builder.Io · @Builder.Io/Qwik-City
Finalgamer
·
Published
2025-07-09
·
Updated
2025-07-11
·
CVE-2025-53620
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H |
Name of the Vulnerable Software and Affected Versions:
@builder.io/qwik-city versions prior to 1.13.0
Description:
The @builder.io/qwik-city meta-framework for Qwik is susceptible to an issue where improper handling of invalid
qfunc during the execution of a Qwik Server Action QRL can lead to a Node.js process exit. This occurs because the server does not manage errors thrown when an invalid qfunc is encountered.Recommendations:
Update to version 1.13.0 or later.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Builder.Io/Qwik-City