VDB
Sign up
MEDIUM6.1

GHSA-hm7f-rq7q-j9xp

@builder.io/qwik vulnerable to Cross-site Scripting

Quick fix

GHSA-hm7f-rq7q-j9xp — @builder.io/qwik: upgrade to the fixed version with the command below.

npm install @builder.io/qwik@0.16.2

Details

@builder.io/qwik prior to version 0.16.2 is vulnerable to cross-site scripting due to attribute names and the class attribute values not being properly handled.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@builder.io/qwik
Introduced in: 0Fixed in: 0.16.2
Fixnpm install @builder.io/qwik@0.16.2

References