PT-2026-6275 · Builder.Io+1 · @Builder.Io/Qwik-City+1
Yueyuel
·
Published
2026-02-03
·
Updated
2026-02-04
·
CVE-2026-25150
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Qwik versions prior to 1.19.0
Description
Qwik is a performance focused javascript framework. A prototype pollution issue exists in the
formToObj() function within the @builder.io/qwik-city middleware. The function processes form field names using dot notation, but does not sanitize dangerous property names like proto, constructor, and prototype. This allows unauthenticated attackers to pollute Object.prototype by sending crafted HTTP POST requests, potentially leading to privilege escalation, authentication bypass, or denial of service.Recommendations
Update to version 1.19.0 or later.
Exploit
Fix
LPE
DoS
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Builder.Io/Qwik-City
Qwik