Product
high
advisory
Quasar Framework SSR/SSG Development Server Information Disclosure and HTML Injection
2 TTPs 1 CVEThe Quasar Framework development server exposes environment variables, cookies, and request headers via an unauthenticated error page that is also susceptible to HTML injection due to an incomplete sanitization routine.
@quasar/render-ssr-error +1
vulnerability
cve
web-application
quasar
2t
1c
high
advisory
Insecure Local TLS Private Key Storage in Quasar Framework
1 TTP 1 CVEThe @quasar/ssl-certificate development utility caches TLS private keys with overly permissive filesystem permissions, enabling local unauthorized access and impersonation of development endpoints.
@quasar/ssl-certificate +2
credential-access
development-tooling
1t
1c