@builder.io/qwik
cpe:2.3:a:builder:qwik:*:*:*:*:*:*:*
- <= 1.19.0
A remote code execution vulnerability exists in Qwik versions through 1.19.0. This issue arises from an unsafe deserialization in the server$ RPC mechanism, allowing any unauthenticated user to execute arbitrary code on the server with a single HTTP request. The vulnerability affects deployments where require() is available at runtime.
Exploitation of this vulnerability allows for remote code execution on the server.
Users can upgrade to Qwik version 1.19.1 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.