CRITICAL9.8
GHSA-9wf9-qvvp-2929
builderio/qwik is vulnerable to code injection
Quick fix
GHSA-9wf9-qvvp-2929 — @builder.io/qwik: upgrade to the fixed version with the command below.
npm install @builder.io/qwik@0.21.0Details
Code Injection in GitHub repository builderio/qwik prior to 0.21.0. The Function deserializer can be accessed using the pureServerFunction feature. This allows any Javascript code to be run by node.js.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-1283[ADVISORY]
- https://github.com/BuilderIO/qwik/pull/3249/commits/4d9ba6e098ae6e537aa55abb6b8369bb670ffe66[WEB]
- https://github.com/builderio/qwik/commit/4d9ba6e098ae6e537aa55abb6b8369bb670ffe66[WEB]
- https://github.com/BuilderIO/qwik[PACKAGE]
- https://huntr.dev/bounties/63f1ff91-48f3-4886-a179-103f1ddd8ff8[WEB]