Description
Description A Cross-site Scripting (CWE-79) vulnerability in Qwik.js’ server-side rendering virtual attribute serialization allows a remote attacker to inject arbitrary web scripts into server-rendered pages via virtual attributes. Successful exploitation permits script execution in a victim’s browser in the context of the affected origin.
Recommendation
Update the @builder.io/qwik-city package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.19.0
- Patched version(s): 1.19.0
References
Could your website be exposed too?
SmartScanner can check your website for Qwik SSR XSS via Unsafe Virtual Node Serialization and gives you actionable findings to investigate.
Start a free scanRelated Issues
- xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion - xmldom - CVE-2026-34601
- Prototype Pollution via FormData Processing in Qwik City - CVE-2026-25150
- Qwik City has a CSRF Protection Bypass via Content-Type Header Validation - CVE-2026-25151
- Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers - CVE-2026-27902


