CCB Alert@CCBalertDisclosure
A critical prototype pollution flaw (CVE-2026-25150) with CVSS 9.3 in Qwik allows unauthenticated attackers to achieve privilege escalation, authentication bypass, or denial of service, and a patch is being referenced.
CVE@CVEnewDisclosure
The post announces a prototype pollution flaw in Qwik's formToObj() function that impacts versions prior to 1.19.0.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The entry announces a prototype‑pollution flaw in Qwik Framework versions before 1.19.0, without providing exploit details, active exploitation evidence, or patch information.
The Hacker Wire@TheHackerWireDisclosure
The post discloses a critical prototype pollution vulnerability (CVE-2026-25150) in Qwik's formToObj() function prior to version 1.19.0, with no evidence of exploitation or patch information provided.
0day Signal@0dayPublishingDisclosure
The post announces a prototype pollution flaw in Qwik City's formToObj() function that allows unauthenticated Object.prototype pollution via FormData, with no PoC, exploit, or patch details provided.