OsVault/npm/@builder.io/qwik-city
npm

@builder.io/qwik-city

7 known vulnerabilities · 0 critical · 0 high

CVE-2026-25149

Qwik City Open Redirect via fixTrailingSlash

Published Feb 3, 2026
CVE-2023-2307MEDIUM

@builder.io/qwik-city Cross-Site Request Forgery vulnerability

Published Apr 26, 2023
CVE-2026-25151

Qwik City has a CSRF Protection Bypass via Content-Type Header Validation

Published Feb 3, 2026
CVE-2026-25155

Qwik City CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)

Published Feb 3, 2026
CVE-2026-32701

Qwik City has array method pollution in FormData processing allows type confusion and DoS

Published Mar 20, 2026
CVE-2026-25148

Qwik SSR XSS via Unsafe Virtual Node Serialization

Published Feb 3, 2026
CVE-2026-25150

Prototype Pollution via FormData Processing in Qwik City

Published Feb 3, 2026
Check your entire dependency tree at onceRun dependency scan →