#VU122438 Prototype pollution in Qwik - CVE-2026-25150
Published: February 6, 2026
Qwik
Builder.io
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper input validation in the formToObj() function within @builder.io/qwik-city middleware. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in privilege escalation and denial of service (DoS) condition.