August 1, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-27971NVD

Vulnerability Summary

Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any deployment where require() is available at runtime. This vulnerability is fixed in 1.19.1.
Severity Level
CRITICAL(9.2)
Published Date
Mar 3, 2026
Last Modified
Mar 3, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
23.12%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v4.0 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone