Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any deployment where require() is available at runtime. This vulnerability is fixed in 1.19.1.
History

Tue, 03 Mar 2026 23:15:00 +0000

Type Values Removed Values Added
Description Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any deployment where require() is available at runtime. This vulnerability is fixed in 1.19.1.
Title Qwik affected by unauthenticated RCE via server$ Deserialization
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-03T22:55:38.064Z

Reserved: 2026-02-25T03:24:57.793Z

Link: CVE-2026-27971

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-03T23:15:56.227

Modified: 2026-03-03T23:15:56.227

Link: CVE-2026-27971

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.