Description
Description A Cross-site Scripting (CWE-79) vulnerability in Qwik.js’ server-side rendering virtual attribute serialization allows a remote attacker to inject arbitrary web scripts into server-rendered pages via virtual attributes. Successful exploitation permits script execution in a victim’s browser in the context of the affected origin.
Recommendation
Update the @builder.io/qwik-city package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.19.0
- Patched version(s): 1.19.0
References
Related Issues
- xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion - xmldom - CVE-2026-34601
- Prototype Pollution via FormData Processing in Qwik City - CVE-2026-25150
- Qwik City has a CSRF Protection Bypass via Content-Type Header Validation - CVE-2026-25151
- Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers - CVE-2026-27902
You might also like:
- Tags:
- npm
- @builder.io/qwik-city
Anything's wrong? Let us know Last updated on February 04, 2026


