Qwik vulnerable to Unauthenticated RCE via server$ Deserialization
Description
Published to the GitHub Advisory Database
Mar 2, 2026
Reviewed
Mar 2, 2026
Published by the National Vulnerability Database
Mar 3, 2026
Last updated
Mar 4, 2026
Summary
qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the
server$RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any deployment whererequire()is available at runtime.Impact
References