GHSA-p9x5-jp3h-96mm
CRITICALCVE-2026-27971qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any deployment where require() is available at runtime.
- Affected
- <= 1.19.0
- Fixed in
- 1.19.1
- Weakness
- CWE-502
- Published
- 2026-03-02
- Source
- github