VDB
Sign up
CRITICAL9.8

GHSA-9wf9-qvvp-2929

builderio/qwik is vulnerable to code injection

Quick fix

GHSA-9wf9-qvvp-2929 — @builder.io/qwik: upgrade to the fixed version with the command below.

npm install @builder.io/qwik@0.21.0

Details

Code Injection in GitHub repository builderio/qwik prior to 0.21.0. The Function deserializer can be accessed using the pureServerFunction feature. This allows any Javascript code to be run by node.js.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@builder.io/qwik
Introduced in: 0Fixed in: 0.21.0
Fixnpm install @builder.io/qwik@0.21.0

References