Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-9wf9-qvvp-2929: builderio/qwik is vulnerable to code injection

Code Injection in GitHub repository builderio/qwik prior to 0.21.0. The Function deserializer can be accessed using the pureServerFunction feature. This allows any Javascript code to be run by node.js.

ghsa
#nodejs#js#git#java

builderio/qwik is vulnerable to code injection

Critical severity GitHub Reviewed Published Mar 9, 2023 to the GitHub Advisory Database • Updated Mar 10, 2023

Related news

CVE-2023-1283

Code Injection in GitHub repository builderio/qwik prior to 0.21.0.

ghsa: Latest News

GHSA-8gc2-vq6m-rwjw: Amazon Redshift Python Connector vulnerable to SQL Injection