Vulnerabilities/

Qwik City has array method pollution in FormData processing allows type confusion and DoS

Severity:
High

Description

Summary

Qwik City improperly inferred arrays from dotted form field names during FormData parsing. By submitting mixed array-index and object-property keys for the same path, an attacker could cause user-controlled properties to be written onto values that application code expected to be arrays.

Recommendation

Update the @builder.io/qwik-city package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@builder.io/qwik-city
Anything's wrong? Let us know Last updated on March 20, 2026