<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Quasar - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/quasar/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 16:59:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/quasar/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Quasar Framework App Vite SSR and SSG Nonce Attribute Injection</title><link>https://feed.craftedsignal.io/briefs/2026-10-quasar-app-vite-nonce-injection/</link><pubDate>Wed, 07 Oct 2026 16:59:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-quasar-app-vite-nonce-injection/</guid><description>The @quasar/app-vite package (&lt;= 3.2.0) is vulnerable to attribute injection in SSR and SSG renderer paths where unsanitized nonce values can be used to inject arbitrary HTML attributes.</description><content:encoded><![CDATA[<p>The Quasar Framework package @quasar/app-vite is susceptible to an attribute injection vulnerability (CVE-2026-106107) within its server-side rendering (SSR) and static site generation (SSG) processes. The vulnerability exists because the <code>ssrContext.nonce</code> variable is interpolated directly into HTML attributes without adequate validation or sanitization. If a web application utilizing this framework allows untrusted user-supplied data to influence or override the <code>ssrContext.nonce</code> field, an attacker can provide a string containing quote characters (e.g., <code>&quot;</code> or <code>'</code>) to terminate the attribute prematurely and inject additional malicious HTML attributes or markup. While cryptographically standard base64/base64url nonces are inherently safe, the lack of programmatic constraints on this input field enables potential cross-site scripting (XSS) or DOM-based injection scenarios in misconfigured applications.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an attacker to inject arbitrary HTML attributes or elements into the rendered output of a Quasar application. Depending on the application's implementation and the injected content, this could lead to the execution of unauthorized JavaScript, manipulation of DOM structure, or the bypass of Content Security Policy (CSP) protections if the nonce mechanism is compromised. The vulnerability affects all versions of @quasar/app-vite up to and including 3.2.0.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update @quasar/app-vite to the latest version that implements centralized nonce handling, which enforces strict base64/base64url validation and HTML encoding of the nonce attribute.</li>
<li>Audit existing applications using the Quasar framework to ensure that no untrusted user input is being passed into <code>ssrContext.nonce</code> within the server-side rendering configuration.</li>
<li>Implement a robust Content Security Policy (CSP) that does not rely solely on dynamically generated nonces from potentially unsafe inputs if the application architecture cannot guarantee input sanitization.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>injection</category><category>app-vite</category><category>quasar</category><category>cve-2026-106107</category></item><item><title>Quasar Framework SSR/SSG Development Server Information Disclosure and HTML Injection</title><link>https://feed.craftedsignal.io/briefs/2026-10-quasar-ssr-disclosure/</link><pubDate>Wed, 07 Oct 2026 16:59:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-quasar-ssr-disclosure/</guid><description>The Quasar Framework development server exposes environment variables, cookies, and request headers via an unauthenticated error page that is also susceptible to HTML injection due to an incomplete sanitization routine.</description><content:encoded><![CDATA[<p>The Quasar Framework development server, used in SSR and SSG modes, contains a critical information disclosure vulnerability (CVE-2026-106106) in the <code>renderSSRError</code> utility. When a rendering exception occurs during development, the framework serializes sensitive data including the full shell environment (<code>process.env</code>), all request headers, and all cookies into an HTTP 500 error page. Because the Quasar CLI overrides the Vite default <code>localhost</code> binding to listen on <code>0.0.0.0</code>, this sensitive information is exposed to any network host capable of reaching the development port.</p>
<p>Furthermore, the error page embeds this serialized data within a <code>&lt;script&gt;</code> element using a flawed string replacement routine (<code>replaceAll('&lt;/script&gt;', ...)</code>). This filter is ASCII-case-sensitive and fails to identify variations such as <code>&lt;/SCRIPT&gt;</code>, <code>&lt;/script &gt;</code>, or <code>&lt;/script/&gt;</code>, allowing an attacker to escape the script context and execute arbitrary JavaScript in the origin of the development server. This issue affects <code>@quasar/render-ssr-error</code> versions 2.2.3 and below, and <code>@quasar/app-vite</code> versions 3.2.0 and below.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker scans the network for development servers listening on Quasar's default ports or configured ports that are exposed via the <code>0.0.0.0</code> binding.</li>
<li>The attacker triggers a server-side rendering (SSR) or static site generation (SSG) error by sending a malformed request that causes the application logic to throw an exception.</li>
<li>The Quasar development server invokes <code>renderSSRError</code>, which collects the server's environment variables (including cloud credentials, tokens, and database strings) and request metadata.</li>
<li>The framework serializes this information into a 500 error response page.</li>
<li>The attacker retrieves the full environment dump via an unauthenticated GET request.</li>
<li>To achieve code execution, the attacker provides a malicious payload in an HTTP header or a cookie that, when processed by the disclosure page, breaks out of the script tag using an unescaped tag like <code>&lt;/SCRIPT &gt;</code>.</li>
<li>The developer's browser renders the malicious script, allowing the attacker to execute code in the local dev environment context.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the unauthorized exfiltration of highly sensitive development credentials, including AWS secret keys, GitHub or NPM registry tokens, and database connection strings. By chaining the information disclosure with the HTML injection vulnerability, an attacker can also gain JavaScript execution within the developer's browser, potentially leading to session hijacking or local file interactions. This represents a significant risk for any organization utilizing Quasar in a networked development environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade affected projects to versions of <code>@quasar/render-ssr-error</code> and <code>@quasar/app-vite</code> that include the patch for CVE-2026-106106.</li>
<li>Ensure the development server is configured to bind to <code>127.0.0.1</code> rather than <code>0.0.0.0</code> to restrict access to the local machine.</li>
<li>Implement strict network segmentation for development environments to prevent unauthorized network access to local development ports.</li>
<li>Audit local development environments for potential credential leakage if the vulnerable version was previously exposed to any untrusted network segments.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>cve</category><category>web-application</category><category>quasar</category></item></channel></rss>