vulns.co
/
GKData.io MCP

QwikDev · 1 min read

Qwik: resumability metadata must preserve HTML serialization boundaries

The maintainer describes unsafe serialization of virtual-component metadata into server-rendered HTML comments. Application-controlled attributes could cross from serialized state into browser interpretation when user influence reached their names or values. The reported impact is same-origin browser script execution, with possible resumability-state disruption. The advisory does not document a production compromise or independently measured downstream data loss.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

The maintainer identifies 1.19.0 as patched. Editorial lesson: serialization safety depends on the actual browser context, including structural metadata and comment boundaries, rather than only visible text or conventional attributes. Review all server-to-client state representations and preserve the contract between their encoder and consumer. A patch for this mechanism is not proof that every application output path is safe.

Before reading

  • Server-rendered HTML and browser parsing contexts
  • Framework resumability and serialized component metadata

Context and limits

  • CVE-2026-25148. Varixo published the advisory; wodzen is credited as reporter.
  • The application prerequisite is user influence over dynamically populated virtual-node attribute names or values. The maintainer excludes hard-coded attributes.
  • The package table names qwik, while the prose names qwik-city. Preserve this naming inconsistency rather than inferring package equivalence.
  • Advisory publication is February 3, 2026. The exact software patch release date was not established and is not substituted into resource-edition chronology.
  • The reviewed official core changelog contains a 1.19.0 section but does not independently explain this security fix. Remediation attribution rests on the maintainer advisory.
  • No bounty is established. Learning prerequisites and generalized defensive guidance are editorial.

Sources and provenance

  1. Qwik SSR XSS via Unsafe Virtual Node Serialization QwikDev · reviewed 2026-10-03
  2. Qwik core changelog QwikDev · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software