{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aquasarapp_vite/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:quasar:app_vite:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-106107"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["app-vite (\u003c= 3.2.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","injection","app-vite","quasar","cve-2026-106107"],"_cs_type":"advisory","_cs_vendors":["Quasar"],"content_html":"\u003cp\u003eThe Quasar Framework package @quasar/app-vite is susceptible to an attribute injection vulnerability (CVE-2026-106107) within its server-side rendering (SSR) and static site generation (SSG) processes. The vulnerability exists because the \u003ccode\u003essrContext.nonce\u003c/code\u003e variable is interpolated directly into HTML attributes without adequate validation or sanitization. If a web application utilizing this framework allows untrusted user-supplied data to influence or override the \u003ccode\u003essrContext.nonce\u003c/code\u003e field, an attacker can provide a string containing quote characters (e.g., \u003ccode\u003e\u0026quot;\u003c/code\u003e or \u003ccode\u003e'\u003c/code\u003e) to terminate the attribute prematurely and inject additional malicious HTML attributes or markup. While cryptographically standard base64/base64url nonces are inherently safe, the lack of programmatic constraints on this input field enables potential cross-site scripting (XSS) or DOM-based injection scenarios in misconfigured applications.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to inject arbitrary HTML attributes or elements into the rendered output of a Quasar application. Depending on the application's implementation and the injected content, this could lead to the execution of unauthorized JavaScript, manipulation of DOM structure, or the bypass of Content Security Policy (CSP) protections if the nonce mechanism is compromised. The vulnerability affects all versions of @quasar/app-vite up to and including 3.2.0.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate @quasar/app-vite to the latest version that implements centralized nonce handling, which enforces strict base64/base64url validation and HTML encoding of the nonce attribute.\u003c/li\u003e\n\u003cli\u003eAudit existing applications using the Quasar framework to ensure that no untrusted user input is being passed into \u003ccode\u003essrContext.nonce\u003c/code\u003e within the server-side rendering configuration.\u003c/li\u003e\n\u003cli\u003eImplement a robust Content Security Policy (CSP) that does not rely solely on dynamically generated nonces from potentially unsafe inputs if the application architecture cannot guarantee input sanitization.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T16:59:24Z","date_published":"2026-10-07T16:59:24Z","id":"https://feed.craftedsignal.io/briefs/2026-10-quasar-app-vite-nonce-injection/","summary":"The @quasar/app-vite package (\u003c= 3.2.0) is vulnerable to attribute injection in SSR and SSG renderer paths where unsanitized nonce values can be used to inject arbitrary HTML attributes.","title":"Quasar Framework App Vite SSR and SSG Nonce Attribute Injection","url":"https://feed.craftedsignal.io/briefs/2026-10-quasar-app-vite-nonce-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:quasar:app_vite:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}