npm
@builder.io/qwik-city
7 known vulnerabilities · 0 critical · 0 high
CVE-2023-2307MEDIUM
@builder.io/qwik-city Cross-Site Request Forgery vulnerability
Published Apr 26, 2023
Qwik City has a CSRF Protection Bypass via Content-Type Header Validation
Published Feb 3, 2026
Qwik City CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)
Published Feb 3, 2026
Qwik City has array method pollution in FormData processing allows type confusion and DoS
Published Mar 20, 2026
Check your entire dependency tree at onceRun dependency scan →