Vendor
Quasar Framework App Vite SSR and SSG Nonce Attribute Injection
1 TTP 1 CVEThe @quasar/app-vite package (<= 3.2.0) is vulnerable to attribute injection in SSR and SSG renderer paths where unsanitized nonce values can be used to inject arbitrary HTML attributes.
Quasar Framework SSR/SSG Development Server Information Disclosure and HTML Injection
2 TTPs 1 CVEThe Quasar Framework development server exposes environment variables, cookies, and request headers via an unauthenticated error page that is also susceptible to HTML injection due to an incomplete sanitization routine.
Insecure Local TLS Private Key Storage in Quasar Framework
1 TTP 1 CVEThe @quasar/ssl-certificate development utility caches TLS private keys with overly permissive filesystem permissions, enabling local unauthorized access and impersonation of development endpoints.
Stored/Reflected XSS in Quasar Framework SSR via Unescaped Meta Tag Rendering
2 TTPs 1 CVEThe Quasar Framework's server-side rendering (SSR) mechanism in versions prior to 2.22.0 fails to escape HTML characters in meta tags, allowing attackers to inject and execute arbitrary JavaScript in the victim's browser.