Skip to content
Threat Feed
high advisory

Stored/Reflected XSS in Quasar Framework SSR via Unescaped Meta Tag Rendering

The Quasar Framework's server-side rendering (SSR) mechanism in versions prior to 2.22.0 fails to escape HTML characters in meta tags, allowing attackers to inject and execute arbitrary JavaScript in the victim's browser.

CVE search metadata

CVE search record: CVE-2026-106102. Severity: critical. CVSS: 10.0. KEV: no. Product: Quasar Framework (< 2.22.0). Brief: Stored/Reflected XSS in Quasar Framework SSR via Unescaped Meta Tag Rendering. Brief link: https://feed.craftedsignal.io/briefs/2026-10-quasar-xss/

Quasar Framework versions prior to 2.22.0 contain a critical vulnerability in the server-side rendering (SSR) utility getHead(), located in ui/src/plugins/meta/Meta.js. This function is responsible for serializing metadata - such as page titles, meta descriptions, and link tags - collected via the useMeta() composable into raw HTML for initial server-side rendering.

The vulnerability exists because getHead() uses insecure template-literal interpolation to construct HTML strings without any HTML-entity or attribute-quote escaping. In contrast, the client-side apply() method uses safe DOM APIs (document.createElement and setAttribute) that handle escaping automatically. Because getHead() is a parallel, independent implementation for the SSR path, it remains vulnerable. An attacker can input strings containing HTML metacharacters (e.g., </title>, ", >) through any application input that eventually populates useMeta(), resulting in the injection of arbitrary malicious markup, including <script> tags, into the server-rendered HTML response.

Attack Chain

  1. Attacker identifies an application input field (e.g., blog post title, user display name, or CMS field) that is processed and rendered by the Quasar SSR useMeta() composable.
  2. Attacker submits a payload containing malicious HTML characters, such as My Post</title><script>alert(document.cookie)</script>.
  3. The application backend stores this malicious string in the database or passes it to the SSR rendering pipeline.
  4. A victim requests the page, triggering the Quasar SSR getHead() utility on the server.
  5. The getHead() function serializes the malicious payload into the raw HTML <head> segment without escaping characters.
  6. The server sends the unsanitized HTML response to the victim's browser.
  7. The browser parses the injected <script> tag before hydration, executing the attacker-supplied JavaScript in the context of the site origin.
  8. The script performs malicious actions such as exfiltrating document.cookie or overlaying phishing content.

Impact

Successful exploitation allows for reflected or stored Cross-Site Scripting (XSS). This gives the attacker the ability to steal user session cookies, perform unauthorized actions on behalf of the user, modify the page content, or redirect users to malicious domains. The vulnerability is highly impactful because useMeta() is a primary and common component used in almost all dynamic Quasar SSR applications, making a wide range of content-heavy sites potentially susceptible to trivial exploitation.

Recommendation

Prioritized actions for development and security engineering teams:

  • Update the Quasar Framework to version 2.22.0 or later immediately to patch CVE-2026-106102.
  • Audit existing SSR implementations for useMeta() usage where user-controlled input might be processed and rendered server-side.
  • Implement a rigorous server-side HTML-escaping routine for all metadata attributes if an immediate framework update is not possible.

Immediate actions

Upgrade Quasar Framework to version 2.22.0 or later

Development 24h

Mitigations

Upgrade Quasar Framework to 2.22.0 or later

immediate IT Operations

CVE-2026-106102