<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>@Vue/Server-Renderer (&lt;= 3.5.41) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/@vue/server-renderer--3.5.41/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 00:46:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/@vue/server-renderer--3.5.41/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in @vue/server-renderer via Attribute Name Injection</title><link>https://feed.craftedsignal.io/briefs/2026-10-vue-ssr-xss/</link><pubDate>Tue, 06 Oct 2026 00:46:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-vue-ssr-xss/</guid><description>An insufficient character blacklist in @vue/server-renderer allows attackers to inject arbitrary HTML attributes by including carriage return characters in dynamic binding keys.</description><content:encoded><![CDATA[<p>The <code>@vue/server-renderer</code> package (version 3.5.41 and earlier) contains a vulnerability in its server-side rendering (SSR) logic that permits stored Cross-Site Scripting (XSS). The function <code>ssrRenderDynamicAttr</code>, which handles dynamic attributes bound via <code>v-bind</code>, relies on an attribute name validation utility (<code>isSSRSafeAttrName</code>) to sanitize keys. This utility utilizes a blacklist that fails to include the carriage return character (U+000D).</p>
<p>Because web browsers perform HTML input stream preprocessing - converting carriage returns not followed by line feeds into line feeds - an attacker who can influence the keys in a bound object can supply a string containing <code>\r</code>. This character terminates the intended attribute name and allows for the injection of new, arbitrary attributes (e.g., <code>autofocus</code> or <code>onfocus</code>) into the rendered HTML output. Since this occurs during the server-side rendering phase, the resulting XSS payload is served directly to users, leading to full script execution in the context of the victim's session without requiring user interaction.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a feature in a web application that renders user-controllable object keys using Vue SSR (e.g., dynamic attribute configuration in a CMS or form builder).</li>
<li>Attacker crafts a malicious input string containing carriage returns (e.g., <code>x\rautofocus\ronfocus</code>) to be used as a key in a dynamic attribute object.</li>
<li>The application passes the malicious object to <code>v-bind</code> or the internal <code>ssrRenderAttrs()</code> function during server-side rendering.</li>
<li>The <code>isSSRSafeAttrName</code> utility validates the key against its blacklist; since <code>\r</code> is not blocked, it marks the key as safe.</li>
<li>The server-side code generates an HTML string where the <code>\r</code> remains embedded in the attribute name (e.g., <code>&lt;div x\rautofocus\ronfocus=&quot;...&quot;&gt;</code>).</li>
<li>The server sends this generated HTML to the victim's browser.</li>
<li>The browser performs HTML input stream normalization, interpreting the <code>\r</code> characters as delimiters, effectively creating new attributes like <code>autofocus</code> and <code>onfocus</code>.</li>
<li>The browser executes the injected JavaScript code (e.g., <code>alert(document.cookie)</code>) upon page load.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full stored XSS within the target application. This allows attackers to execute arbitrary JavaScript in the context of any user viewing the affected page, leading to session hijacking, unauthorized data exfiltration, and potential complete account takeover. The vulnerability is highly severe in SSR contexts where dynamic object binding is used to construct HTML elements from untrusted inputs, such as in administrative dashboards or user-facing portals supporting custom configurations.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the following actions for your development and security teams:</p>
<ul>
<li>Upgrade <code>@vue/server-renderer</code> to a patched version that explicitly blacklists carriage return (U+000D) characters in <code>isSSRSafeAttrName</code>.</li>
<li>Perform a code audit of all SSR-enabled Vue components to identify instances where <code>v-bind</code> or <code>ssrRenderAttrs</code> processes objects with keys derived from external data.</li>
<li>Implement strict allowlists for dynamic attribute names where user input is involved, rather than relying solely on blacklisting unsafe characters.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>xss</category><category>web-application</category><category>vue</category><category>ssr</category><category>code-vulnerability</category></item></channel></rss>