CVE-2026-32701: Qwik City Formdata Array Pollution

During nested structure parsing, the code determines whether to instantiate an array or object purely by looking ahead at the next key using `Number.isNaN` or `isNaN`. This logic allows an attacker to mix array-index and object-property keys on the same path, tricking the parser into instantiating an array and subsequently injecting arbitrary properties on i

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0JS
greprules fetch cve-2026-32701-qwik-city-formdata-array-pollution --engine opengrep

Description

During nested structure parsing, the code determines whether to instantiate an array or object purely by looking ahead at the next key using `Number.isNaN` or `isNaN`. This logic allows an attacker to mix array-index and object-property keys on the same path, tricking the parser into instantiating an array and subsequently injecting arbitrary properties on i