Qwik <=1.19.0 contains an insecure deserialization vulnerability in the server$ RPC mechanism, letting unauthenticated attackers execute arbitrary code remotely, exploit requires require() availability at runtime.
id: CVE-2026-27971
info:
name: Qwik - Unauthenticated RCE via server$ Deserialization
author: o
...