@builder.io/qwik-city is the meta-framework for Qwik. When a Qwik Server Action QRL is executed it dynamically load the file containing the symbol. When an invalid qfunc is sent, the server does not handle the thrown error. The error then causes Node JS to exit. This vulnerability is fixed in 1.13.0.
History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00042}

epss

{'score': 0.00055}


Wed, 09 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Jul 2025 19:00:00 +0000

Type Values Removed Values Added
Description @builder.io/qwik-city is the meta-framework for Qwik. When a Qwik Server Action QRL is executed it dynamically load the file containing the symbol. When an invalid qfunc is sent, the server does not handle the thrown error. The error then causes Node JS to exit. This vulnerability is fixed in 1.13.0.
Title Crashing any Qwik Server
Weaknesses CWE-248
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-09T18:45:28.947Z

Updated: 2025-07-09T19:14:41.333Z

Reserved: 2025-07-07T14:20:38.386Z

Link: CVE-2025-53620

cve-icon Vulnrichment

Updated: 2025-07-09T19:14:10.453Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-09T19:15:24.427

Modified: 2025-07-10T13:17:30.017

Link: CVE-2025-53620

cve-icon Redhat

No data.