VDB
Sign up
MEDIUM5.9

GHSA-r666-8gjf-4v5f

Qwik City has a CSRF Protection Bypass via Content-Type Header Validation

Quick fix

GHSA-r666-8gjf-4v5f — @builder.io/qwik-city: upgrade to the fixed version with the command below.

npm install @builder.io/qwik-city@1.19.0

Details

### Summary Qwik City’s server-side request handler inconsistently interprets HTTP request headers, which can be abused by a remote attacker to circumvent form submission CSRF protections using specially crafted or multi-valued Content-Type headers.

### Impact A vulnerability in checkCSRF lets an attacker bypass Origin-based CSRF checks by using malformed or multi-valued Content-Type headers. Exploitation requires the CORS preflight to succeed (so it’s blocked if preflight is denied) and is possible when the application accepts cross-origin requests or via non-browser clients. Impact varies with server CORS and cookie policies and may enable unauthorized state changes.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@builder.io/qwik-city
Introduced in: 0Fixed in: 1.19.0
Fixnpm install @builder.io/qwik-city@1.19.0

References