Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m6jq-g7gq-5w3c | Qwik SSR XSS via Unsafe Virtual Node Serialization |
Tue, 10 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qwik
Qwik qwik |
|
| CPEs | cpe:2.3:a:qwik:qwik:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Qwik
Qwik qwik |
|
| Metrics |
cvssV3_1
|
Wed, 04 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qwikdev
Qwikdev qwik |
|
| Vendors & Products |
Qwikdev
Qwikdev qwik |
Tue, 03 Feb 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Qwik is a performance focused javascript framework. Prior to version 1.19.0, a Cross-Site Scripting vulnerability in Qwik.js' server-side rendering virtual attribute serialization allows a remote attacker to inject arbitrary web scripts into server-rendered pages via virtual attributes. Successful exploitation permits script execution in a victim's browser in the context of the affected origin. This issue has been patched in version 1.19.0. | |
| Title | Qwik SSR XSS via Unsafe Virtual Node Serialization | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-04T16:58:39.293Z
Reserved: 2026-01-29T15:39:11.821Z
Link: CVE-2026-25148
Updated: 2026-02-04T16:58:34.702Z
Status : Analyzed
Published: 2026-02-03T22:16:30.370
Modified: 2026-02-10T20:12:16.070
Link: CVE-2026-25148
No data.
OpenCVE Enrichment
Updated: 2026-04-18T00:15:31Z
Github GHSA