<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>@Quasar/Ssl-Certificate (&lt;= 2.0.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/@quasar/ssl-certificate--2.0.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 16:59:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/@quasar/ssl-certificate--2.0.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Insecure Local TLS Private Key Storage in Quasar Framework</title><link>https://feed.craftedsignal.io/briefs/2026-10-quasar-ssl-vuln/</link><pubDate>Wed, 07 Oct 2026 16:59:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-quasar-ssl-vuln/</guid><description>The @quasar/ssl-certificate development utility caches TLS private keys with overly permissive filesystem permissions, enabling local unauthorized access and impersonation of development endpoints.</description><content:encoded><![CDATA[<p>The Quasar Framework development utility, specifically the @quasar/ssl-certificate package, contains a security vulnerability (CVE-2026-106105) related to how it handles cached development TLS private keys. When the utility generates and caches a combined PEM file containing a private key and its associated certificate, it fails to explicitly restrict filesystem permissions. Consequently, on many systems, the resulting file is readable by other local users depending on the system's umask settings.</p>
<p>Furthermore, the generated certificates were identified as having overly broad security parameters, including CA-capability and excessive key usage. An attacker with local filesystem access can read the cached private key and use it to impersonate a development TLS endpoint in environments where the certificate is trusted. This issue impacts several Quasar components, including the CLI and Vite application packages, which utilize this utility for local development environments. Remediation involves ensuring the cached PEM files are written with owner-only permissions and updating certificate generation logic to constrain key usage and remove CA-capability.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a local attacker to obtain a valid private TLS key used in development environments. This enables the attacker to perform machine-in-the-middle attacks or impersonate local development services that rely on these certificates for trust. This risk is primarily relevant in multi-user development environments, shared build servers, or local workstations where malicious actors have already established a foothold or have legitimate local access.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize updating all instances of @quasar/ssl-certificate, @quasar/cli, and @quasar/app-vite to versions that address CVE-2026-106105. For environments where upgrades are delayed, implement strict local filesystem permission audits on development directories where Quasar projects reside.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>credential-access</category><category>development-tooling</category></item></channel></rss>