{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aquasarrender-ssr-error/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:quasar:render-ssr-error:*:*:*:*:*:*:*:*","cpe:2.3:a:quasar:app-vite:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-106106"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@quasar/render-ssr-error (\u003c= 2.2.3)","@quasar/app-vite (\u003c= 3.2.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cve","web-application","quasar"],"_cs_type":"advisory","_cs_vendors":["Quasar"],"content_html":"\u003cp\u003eThe Quasar Framework development server, used in SSR and SSG modes, contains a critical information disclosure vulnerability (CVE-2026-106106) in the \u003ccode\u003erenderSSRError\u003c/code\u003e utility. When a rendering exception occurs during development, the framework serializes sensitive data including the full shell environment (\u003ccode\u003eprocess.env\u003c/code\u003e), all request headers, and all cookies into an HTTP 500 error page. Because the Quasar CLI overrides the Vite default \u003ccode\u003elocalhost\u003c/code\u003e binding to listen on \u003ccode\u003e0.0.0.0\u003c/code\u003e, this sensitive information is exposed to any network host capable of reaching the development port.\u003c/p\u003e\n\u003cp\u003eFurthermore, the error page embeds this serialized data within a \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e element using a flawed string replacement routine (\u003ccode\u003ereplaceAll('\u0026lt;/script\u0026gt;', ...)\u003c/code\u003e). This filter is ASCII-case-sensitive and fails to identify variations such as \u003ccode\u003e\u0026lt;/SCRIPT\u0026gt;\u003c/code\u003e, \u003ccode\u003e\u0026lt;/script \u0026gt;\u003c/code\u003e, or \u003ccode\u003e\u0026lt;/script/\u0026gt;\u003c/code\u003e, allowing an attacker to escape the script context and execute arbitrary JavaScript in the origin of the development server. This issue affects \u003ccode\u003e@quasar/render-ssr-error\u003c/code\u003e versions 2.2.3 and below, and \u003ccode\u003e@quasar/app-vite\u003c/code\u003e versions 3.2.0 and below.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker scans the network for development servers listening on Quasar's default ports or configured ports that are exposed via the \u003ccode\u003e0.0.0.0\u003c/code\u003e binding.\u003c/li\u003e\n\u003cli\u003eThe attacker triggers a server-side rendering (SSR) or static site generation (SSG) error by sending a malformed request that causes the application logic to throw an exception.\u003c/li\u003e\n\u003cli\u003eThe Quasar development server invokes \u003ccode\u003erenderSSRError\u003c/code\u003e, which collects the server's environment variables (including cloud credentials, tokens, and database strings) and request metadata.\u003c/li\u003e\n\u003cli\u003eThe framework serializes this information into a 500 error response page.\u003c/li\u003e\n\u003cli\u003eThe attacker retrieves the full environment dump via an unauthenticated GET request.\u003c/li\u003e\n\u003cli\u003eTo achieve code execution, the attacker provides a malicious payload in an HTTP header or a cookie that, when processed by the disclosure page, breaks out of the script tag using an unescaped tag like \u003ccode\u003e\u0026lt;/SCRIPT \u0026gt;\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe developer's browser renders the malicious script, allowing the attacker to execute code in the local dev environment context.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the unauthorized exfiltration of highly sensitive development credentials, including AWS secret keys, GitHub or NPM registry tokens, and database connection strings. By chaining the information disclosure with the HTML injection vulnerability, an attacker can also gain JavaScript execution within the developer's browser, potentially leading to session hijacking or local file interactions. This represents a significant risk for any organization utilizing Quasar in a networked development environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade affected projects to versions of \u003ccode\u003e@quasar/render-ssr-error\u003c/code\u003e and \u003ccode\u003e@quasar/app-vite\u003c/code\u003e that include the patch for CVE-2026-106106.\u003c/li\u003e\n\u003cli\u003eEnsure the development server is configured to bind to \u003ccode\u003e127.0.0.1\u003c/code\u003e rather than \u003ccode\u003e0.0.0.0\u003c/code\u003e to restrict access to the local machine.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation for development environments to prevent unauthorized network access to local development ports.\u003c/li\u003e\n\u003cli\u003eAudit local development environments for potential credential leakage if the vulnerable version was previously exposed to any untrusted network segments.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-07T16:59:17Z","date_published":"2026-10-07T16:59:17Z","id":"https://feed.craftedsignal.io/briefs/2026-10-quasar-ssr-disclosure/","summary":"The Quasar Framework development server exposes environment variables, cookies, and request headers via an unauthenticated error page that is also susceptible to HTML injection due to an incomplete sanitization routine.","title":"Quasar Framework SSR/SSG Development Server Information Disclosure and HTML Injection","url":"https://feed.craftedsignal.io/briefs/2026-10-quasar-ssr-disclosure/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:quasar:render-Ssr-Error:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}