VDB
Sign up
CRITICAL9.3

GHSA-xqg6-98cw-gxhq

Prototype Pollution via FormData Processing in Qwik City

Quick fix

GHSA-xqg6-98cw-gxhq — @builder.io/qwik-city: upgrade to the fixed version with the command below.

npm install @builder.io/qwik-city@1.19.0

Details

### Summary

A Prototype Pollution vulnerability exists in the `formToObj()` function within `@builder.io/qwik-city` middleware. The function processes form field names with dot notation (e.g., `user.name`) to create nested objects, but fails to sanitize dangerous property names like `__proto__`, `constructor`, and `prototype`. This allows unauthenticated attackers to pollute `Object.prototype` by sending crafted HTTP POST requests, potentially leading to privilege escalation, authentication bypass, or denial of service.

### Impact An unauthenticated attacker can supply specially crafted form field names that cause formToObj() to write dangerous keys (for example __proto__, constructor, prototype) into parsed objects. This results in Prototype Pollution of the server process and can cause privilege escalation, auth bypass, denial-of-service, or other global application integrity failures depending on how objects are used.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@builder.io/qwik-city
Introduced in: 0Fixed in: 1.19.0
Fixnpm install @builder.io/qwik-city@1.19.0

References