PT-2026-6275 · Builder.Io+1 · @Builder.Io/Qwik-City+1

Yueyuel

·

Published

2026-02-03

·

Updated

2026-02-04

·

CVE-2026-25150

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Qwik versions prior to 1.19.0
Description Qwik is a performance focused javascript framework. A prototype pollution issue exists in the formToObj() function within the @builder.io/qwik-city middleware. The function processes form field names using dot notation, but does not sanitize dangerous property names like proto, constructor, and prototype. This allows unauthenticated attackers to pollute Object.prototype by sending crafted HTTP POST requests, potentially leading to privilege escalation, authentication bypass, or denial of service.
Recommendations Update to version 1.19.0 or later.

Exploit

Fix

LPE

DoS

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2026-25150
GHSA-XQG6-98CW-GXHQ

Affected Products

@Builder.Io/Qwik-City
Qwik