CVE-2026-25150Disclosure(qwik / qwik)

LOWCVSS 10.0 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch qwik qwik systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city middleware. The function processes form field names with dot notation (e.g., user.name) to create nested objects, but fails to sanitize dangerous property names like __proto__, constructor, and prototype. This allows unauthenticated attackers to pollute Object.prototype by sending crafted HTTP POST requests, potentially leading to privilege escalation, authentication bypass, or denial of service. This issue has been patched in version 1.19.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • qwik

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-02-04)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
qwik

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-02-03: 2Mentions · 2026-02-04: 3Patch / Workaround · 2026-02-04: 1Technical Details · 2026-02-03: 2Technical Details · 2026-02-04: 302-0302-04
Signal classification1 categories
Disclosure
5100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-032
Disclosure2
2026-02-043
Disclosure3
Full discourse5 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical prototype pollution vulnerability in #Qwik. CVE-2026-25150 CVSS: 9.3. This vulnerability allows unauthenticated attackers to perform privilege escalation, authentication bypass or denial of service #Patch #Patch #Patch

    Post summary

    A critical prototype pollution flaw (CVE-2026-25150) with CVSS 9.3 in Qwik allows unauthenticated attackers to achieve privilege escalation, authentication bypass, or denial of service, and a patch is being referenced.

    01000225
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25150 Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io… https://www.cve.org/CVERecord?id=CVE-2026-25150

    Post summary

    The post announces a prototype pollution flaw in Qwik's formToObj() function that impacts versions prior to 1.19.0.

    00000186
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25150 Prototype Pollution Vulnerability in Qwik Framework Prior to Version 1.19.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25150

    Post summary

    The entry announces a prototype‑pollution flaw in Qwik Framework versions before 1.19.0, without providing exploit details, active exploitation evidence, or patch information.

    0000061
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25150 - Critical Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city middleware... https://www.thehackerwire.com/vulnerability/CVE-2026-25150/ https://t.co/OEncp8e62A

    Post summary

    The post discloses a critical prototype pollution vulnerability (CVE-2026-25150) in Qwik's formToObj() function prior to version 1.19.0, with no evidence of exploitation or patch information provided.

    0000069
    113 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25150: Prototype Pollution via FormData... Qwik City's formToObj() lacks basic prototype chain protection, enabling trivial unauthenticated Object.prototype pollu... https://zerodaysignal.com/vulnerability/CVE-2026-25150 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a prototype pollution flaw in Qwik City's formToObj() function that allows unauthenticated Object.prototype pollution via FormData, with no PoC, exploit, or patch details provided.

    0000053
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appqwikqwik-node.js-

Explore more