VDB
Sign up
MEDIUM5.9

GHSA-vm6g-8r4h-22x8

Qwik City CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)

Quick fix

GHSA-vm6g-8r4h-22x8 — @builder.io/qwik-city: upgrade to the fixed version with the command below.

npm install @builder.io/qwik-city@1.12.0

Details

### Summary A typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type headers.

### Impact An attacker can bypass Qwik City’s Origin-based CSRF protections and perform forged form submissions, potentially causing unauthorized state changes.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@builder.io/qwik-city
Introduced in: 0Fixed in: 1.12.0
Fixnpm install @builder.io/qwik-city@1.12.0

References