Tag
high
advisory
Quasar Framework App Vite SSR and SSG Nonce Attribute Injection
1 TTP 1 CVEThe @quasar/app-vite package (<= 3.2.0) is vulnerable to attribute injection in SSR and SSG renderer paths where unsanitized nonce values can be used to inject arbitrary HTML attributes.
app-vite
web-vulnerability
injection
quasar
cve-2026-106107
1t
1c
high
advisory
Quasar Framework SSR/SSG Development Server Information Disclosure and HTML Injection
2 TTPs 1 CVEThe Quasar Framework development server exposes environment variables, cookies, and request headers via an unauthenticated error page that is also susceptible to HTML injection due to an incomplete sanitization routine.
@quasar/render-ssr-error +1
vulnerability
cve
web-application
quasar
2t
1c