CVE-2026-27971
Summary
qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any deployment where require() is available at runtime.
Impact
- Remote Code Execution
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/QwikDev/qwik/security/advisories/GHSA-p9x5-jp3h-96mm, https://nvd.nist.gov/vuln/detail/CVE-2026-27971, https://github.com/QwikDev/qwik, https://github.com/QwikDev/qwik/releases/tag/%40builder.io%2Fqwik%401.19.1
