Qwik affected by unauthenticated RCE via server$ Deserialization
85Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.2epss 5.4%
from disclosure to weapon140 days
Published on NVDMar 3
1st PoC+140d
VulnCheck+29d
exploitation probability
5.4%top 8% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any deployment where require() is available at runtime. This vulnerability is fixed in 1.19.1.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
QwikDev · qwikpublic PoCs found — 1
vulncheckvulncheck.com/xdb/1f87d788a7bbunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.