Insecure Local TLS Private Key Storage in Quasar Framework
The @quasar/ssl-certificate development utility caches TLS private keys with overly permissive filesystem permissions, enabling local unauthorized access and impersonation of development endpoints.
CVE search metadata
CVE search record: CVE-2026-106105. KEV: no. Product: @quasar/ssl-certificate (<= 2.0.0), @quasar/cli (<= 5.0.3), @quasar/app-vite (<= 3.2.0). Brief: Insecure Local TLS Private Key Storage in Quasar Framework. Brief link: https://feed.craftedsignal.io/briefs/2026-10-quasar-ssl-vuln/
The Quasar Framework development utility, specifically the @quasar/ssl-certificate package, contains a security vulnerability (CVE-2026-106105) related to how it handles cached development TLS private keys. When the utility generates and caches a combined PEM file containing a private key and its associated certificate, it fails to explicitly restrict filesystem permissions. Consequently, on many systems, the resulting file is readable by other local users depending on the system's umask settings.
Furthermore, the generated certificates were identified as having overly broad security parameters, including CA-capability and excessive key usage. An attacker with local filesystem access can read the cached private key and use it to impersonate a development TLS endpoint in environments where the certificate is trusted. This issue impacts several Quasar components, including the CLI and Vite application packages, which utilize this utility for local development environments. Remediation involves ensuring the cached PEM files are written with owner-only permissions and updating certificate generation logic to constrain key usage and remove CA-capability.
Impact
Successful exploitation allows a local attacker to obtain a valid private TLS key used in development environments. This enables the attacker to perform machine-in-the-middle attacks or impersonate local development services that rely on these certificates for trust. This risk is primarily relevant in multi-user development environments, shared build servers, or local workstations where malicious actors have already established a foothold or have legitimate local access.
Recommendation
Prioritize updating all instances of @quasar/ssl-certificate, @quasar/cli, and @quasar/app-vite to versions that address CVE-2026-106105. For environments where upgrades are delayed, implement strict local filesystem permission audits on development directories where Quasar projects reside.
Mitigations
Update @quasar/ssl-certificate, @quasar/cli, and @quasar/app-vite to versions containing the fix for CVE-2026-106105.
CVE-2026-106105