{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/quasar/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:quasar:app_vite:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-106107"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["app-vite (\u003c= 3.2.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","injection","app-vite","quasar","cve-2026-106107"],"_cs_type":"advisory","_cs_vendors":["Quasar"],"content_html":"\u003cp\u003eThe Quasar Framework package @quasar/app-vite is susceptible to an attribute injection vulnerability (CVE-2026-106107) within its server-side rendering (SSR) and static site generation (SSG) processes. The vulnerability exists because the \u003ccode\u003essrContext.nonce\u003c/code\u003e variable is interpolated directly into HTML attributes without adequate validation or sanitization. If a web application utilizing this framework allows untrusted user-supplied data to influence or override the \u003ccode\u003essrContext.nonce\u003c/code\u003e field, an attacker can provide a string containing quote characters (e.g., \u003ccode\u003e\u0026quot;\u003c/code\u003e or \u003ccode\u003e'\u003c/code\u003e) to terminate the attribute prematurely and inject additional malicious HTML attributes or markup. While cryptographically standard base64/base64url nonces are inherently safe, the lack of programmatic constraints on this input field enables potential cross-site scripting (XSS) or DOM-based injection scenarios in misconfigured applications.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to inject arbitrary HTML attributes or elements into the rendered output of a Quasar application. Depending on the application's implementation and the injected content, this could lead to the execution of unauthorized JavaScript, manipulation of DOM structure, or the bypass of Content Security Policy (CSP) protections if the nonce mechanism is compromised. The vulnerability affects all versions of @quasar/app-vite up to and including 3.2.0.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate @quasar/app-vite to the latest version that implements centralized nonce handling, which enforces strict base64/base64url validation and HTML encoding of the nonce attribute.\u003c/li\u003e\n\u003cli\u003eAudit existing applications using the Quasar framework to ensure that no untrusted user input is being passed into \u003ccode\u003essrContext.nonce\u003c/code\u003e within the server-side rendering configuration.\u003c/li\u003e\n\u003cli\u003eImplement a robust Content Security Policy (CSP) that does not rely solely on dynamically generated nonces from potentially unsafe inputs if the application architecture cannot guarantee input sanitization.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T16:59:24Z","date_published":"2026-10-07T16:59:24Z","id":"https://feed.craftedsignal.io/briefs/2026-10-quasar-app-vite-nonce-injection/","summary":"The @quasar/app-vite package (\u003c= 3.2.0) is vulnerable to attribute injection in SSR and SSG renderer paths where unsanitized nonce values can be used to inject arbitrary HTML attributes.","title":"Quasar Framework App Vite SSR and SSG Nonce Attribute Injection","url":"https://feed.craftedsignal.io/briefs/2026-10-quasar-app-vite-nonce-injection/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:quasar:render-ssr-error:*:*:*:*:*:*:*:*","cpe:2.3:a:quasar:app-vite:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-106106"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@quasar/render-ssr-error (\u003c= 2.2.3)","@quasar/app-vite (\u003c= 3.2.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cve","web-application","quasar"],"_cs_type":"advisory","_cs_vendors":["Quasar"],"content_html":"\u003cp\u003eThe Quasar Framework development server, used in SSR and SSG modes, contains a critical information disclosure vulnerability (CVE-2026-106106) in the \u003ccode\u003erenderSSRError\u003c/code\u003e utility. When a rendering exception occurs during development, the framework serializes sensitive data including the full shell environment (\u003ccode\u003eprocess.env\u003c/code\u003e), all request headers, and all cookies into an HTTP 500 error page. Because the Quasar CLI overrides the Vite default \u003ccode\u003elocalhost\u003c/code\u003e binding to listen on \u003ccode\u003e0.0.0.0\u003c/code\u003e, this sensitive information is exposed to any network host capable of reaching the development port.\u003c/p\u003e\n\u003cp\u003eFurthermore, the error page embeds this serialized data within a \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e element using a flawed string replacement routine (\u003ccode\u003ereplaceAll('\u0026lt;/script\u0026gt;', ...)\u003c/code\u003e). This filter is ASCII-case-sensitive and fails to identify variations such as \u003ccode\u003e\u0026lt;/SCRIPT\u0026gt;\u003c/code\u003e, \u003ccode\u003e\u0026lt;/script \u0026gt;\u003c/code\u003e, or \u003ccode\u003e\u0026lt;/script/\u0026gt;\u003c/code\u003e, allowing an attacker to escape the script context and execute arbitrary JavaScript in the origin of the development server. This issue affects \u003ccode\u003e@quasar/render-ssr-error\u003c/code\u003e versions 2.2.3 and below, and \u003ccode\u003e@quasar/app-vite\u003c/code\u003e versions 3.2.0 and below.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker scans the network for development servers listening on Quasar's default ports or configured ports that are exposed via the \u003ccode\u003e0.0.0.0\u003c/code\u003e binding.\u003c/li\u003e\n\u003cli\u003eThe attacker triggers a server-side rendering (SSR) or static site generation (SSG) error by sending a malformed request that causes the application logic to throw an exception.\u003c/li\u003e\n\u003cli\u003eThe Quasar development server invokes \u003ccode\u003erenderSSRError\u003c/code\u003e, which collects the server's environment variables (including cloud credentials, tokens, and database strings) and request metadata.\u003c/li\u003e\n\u003cli\u003eThe framework serializes this information into a 500 error response page.\u003c/li\u003e\n\u003cli\u003eThe attacker retrieves the full environment dump via an unauthenticated GET request.\u003c/li\u003e\n\u003cli\u003eTo achieve code execution, the attacker provides a malicious payload in an HTTP header or a cookie that, when processed by the disclosure page, breaks out of the script tag using an unescaped tag like \u003ccode\u003e\u0026lt;/SCRIPT \u0026gt;\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe developer's browser renders the malicious script, allowing the attacker to execute code in the local dev environment context.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the unauthorized exfiltration of highly sensitive development credentials, including AWS secret keys, GitHub or NPM registry tokens, and database connection strings. By chaining the information disclosure with the HTML injection vulnerability, an attacker can also gain JavaScript execution within the developer's browser, potentially leading to session hijacking or local file interactions. This represents a significant risk for any organization utilizing Quasar in a networked development environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade affected projects to versions of \u003ccode\u003e@quasar/render-ssr-error\u003c/code\u003e and \u003ccode\u003e@quasar/app-vite\u003c/code\u003e that include the patch for CVE-2026-106106.\u003c/li\u003e\n\u003cli\u003eEnsure the development server is configured to bind to \u003ccode\u003e127.0.0.1\u003c/code\u003e rather than \u003ccode\u003e0.0.0.0\u003c/code\u003e to restrict access to the local machine.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation for development environments to prevent unauthorized network access to local development ports.\u003c/li\u003e\n\u003cli\u003eAudit local development environments for potential credential leakage if the vulnerable version was previously exposed to any untrusted network segments.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-07T16:59:17Z","date_published":"2026-10-07T16:59:17Z","id":"https://feed.craftedsignal.io/briefs/2026-10-quasar-ssr-disclosure/","summary":"The Quasar Framework development server exposes environment variables, cookies, and request headers via an unauthenticated error page that is also susceptible to HTML injection due to an incomplete sanitization routine.","title":"Quasar Framework SSR/SSG Development Server Information Disclosure and HTML Injection","url":"https://feed.craftedsignal.io/briefs/2026-10-quasar-ssr-disclosure/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-106105"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@quasar/ssl-certificate (\u003c= 2.0.0)","@quasar/cli (\u003c= 5.0.3)","@quasar/app-vite (\u003c= 3.2.0)"],"_cs_severities":["high"],"_cs_tags":["credential-access","development-tooling"],"_cs_type":"advisory","_cs_vendors":["Quasar"],"content_html":"\u003cp\u003eThe Quasar Framework development utility, specifically the @quasar/ssl-certificate package, contains a security vulnerability (CVE-2026-106105) related to how it handles cached development TLS private keys. When the utility generates and caches a combined PEM file containing a private key and its associated certificate, it fails to explicitly restrict filesystem permissions. Consequently, on many systems, the resulting file is readable by other local users depending on the system's umask settings.\u003c/p\u003e\n\u003cp\u003eFurthermore, the generated certificates were identified as having overly broad security parameters, including CA-capability and excessive key usage. An attacker with local filesystem access can read the cached private key and use it to impersonate a development TLS endpoint in environments where the certificate is trusted. This issue impacts several Quasar components, including the CLI and Vite application packages, which utilize this utility for local development environments. Remediation involves ensuring the cached PEM files are written with owner-only permissions and updating certificate generation logic to constrain key usage and remove CA-capability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local attacker to obtain a valid private TLS key used in development environments. This enables the attacker to perform machine-in-the-middle attacks or impersonate local development services that rely on these certificates for trust. This risk is primarily relevant in multi-user development environments, shared build servers, or local workstations where malicious actors have already established a foothold or have legitimate local access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize updating all instances of @quasar/ssl-certificate, @quasar/cli, and @quasar/app-vite to versions that address CVE-2026-106105. For environments where upgrades are delayed, implement strict local filesystem permission audits on development directories where Quasar projects reside.\u003c/p\u003e\n","date_modified":"2026-10-07T16:59:05Z","date_published":"2026-10-07T16:59:05Z","id":"https://feed.craftedsignal.io/briefs/2026-10-quasar-ssl-vuln/","summary":"The @quasar/ssl-certificate development utility caches TLS private keys with overly permissive filesystem permissions, enabling local unauthorized access and impersonation of development endpoints.","title":"Insecure Local TLS Private Key Storage in Quasar Framework","url":"https://feed.craftedsignal.io/briefs/2026-10-quasar-ssl-vuln/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:quasar-framework:quasar:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-106102"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Quasar Framework (\u003c 2.22.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Quasar"],"content_html":"\u003cp\u003eQuasar Framework versions prior to 2.22.0 contain a critical vulnerability in the server-side rendering (SSR) utility \u003ccode\u003egetHead()\u003c/code\u003e, located in \u003ccode\u003eui/src/plugins/meta/Meta.js\u003c/code\u003e. This function is responsible for serializing metadata - such as page titles, meta descriptions, and link tags - collected via the \u003ccode\u003euseMeta()\u003c/code\u003e composable into raw HTML for initial server-side rendering.\u003c/p\u003e\n\u003cp\u003eThe vulnerability exists because \u003ccode\u003egetHead()\u003c/code\u003e uses insecure template-literal interpolation to construct HTML strings without any HTML-entity or attribute-quote escaping. In contrast, the client-side \u003ccode\u003eapply()\u003c/code\u003e method uses safe DOM APIs (\u003ccode\u003edocument.createElement\u003c/code\u003e and \u003ccode\u003esetAttribute\u003c/code\u003e) that handle escaping automatically. Because \u003ccode\u003egetHead()\u003c/code\u003e is a parallel, independent implementation for the SSR path, it remains vulnerable. An attacker can input strings containing HTML metacharacters (e.g., \u003ccode\u003e\u0026lt;/title\u0026gt;\u003c/code\u003e, \u003ccode\u003e\u0026quot;\u003c/code\u003e, \u003ccode\u003e\u0026gt;\u003c/code\u003e) through any application input that eventually populates \u003ccode\u003euseMeta()\u003c/code\u003e, resulting in the injection of arbitrary malicious markup, including \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e tags, into the server-rendered HTML response.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an application input field (e.g., blog post title, user display name, or CMS field) that is processed and rendered by the Quasar SSR \u003ccode\u003euseMeta()\u003c/code\u003e composable.\u003c/li\u003e\n\u003cli\u003eAttacker submits a payload containing malicious HTML characters, such as \u003ccode\u003eMy Post\u0026lt;/title\u0026gt;\u0026lt;script\u0026gt;alert(document.cookie)\u0026lt;/script\u0026gt;\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe application backend stores this malicious string in the database or passes it to the SSR rendering pipeline.\u003c/li\u003e\n\u003cli\u003eA victim requests the page, triggering the Quasar SSR \u003ccode\u003egetHead()\u003c/code\u003e utility on the server.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003egetHead()\u003c/code\u003e function serializes the malicious payload into the raw HTML \u003ccode\u003e\u0026lt;head\u0026gt;\u003c/code\u003e segment without escaping characters.\u003c/li\u003e\n\u003cli\u003eThe server sends the unsanitized HTML response to the victim's browser.\u003c/li\u003e\n\u003cli\u003eThe browser parses the injected \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e tag before hydration, executing the attacker-supplied JavaScript in the context of the site origin.\u003c/li\u003e\n\u003cli\u003eThe script performs malicious actions such as exfiltrating \u003ccode\u003edocument.cookie\u003c/code\u003e or overlaying phishing content.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for reflected or stored Cross-Site Scripting (XSS). This gives the attacker the ability to steal user session cookies, perform unauthorized actions on behalf of the user, modify the page content, or redirect users to malicious domains. The vulnerability is highly impactful because \u003ccode\u003euseMeta()\u003c/code\u003e is a primary and common component used in almost all dynamic Quasar SSR applications, making a wide range of content-heavy sites potentially susceptible to trivial exploitation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for development and security engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Quasar Framework to version 2.22.0 or later immediately to patch CVE-2026-106102.\u003c/li\u003e\n\u003cli\u003eAudit existing SSR implementations for \u003ccode\u003euseMeta()\u003c/code\u003e usage where user-controlled input might be processed and rendered server-side.\u003c/li\u003e\n\u003cli\u003eImplement a rigorous server-side HTML-escaping routine for all metadata attributes if an immediate framework update is not possible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T16:56:46Z","date_published":"2026-10-07T16:56:46Z","id":"https://feed.craftedsignal.io/briefs/2026-10-quasar-xss/","summary":"The Quasar Framework's server-side rendering (SSR) mechanism in versions prior to 2.22.0 fails to escape HTML characters in meta tags, allowing attackers to inject and execute arbitrary JavaScript in the victim's browser.","title":"Stored/Reflected XSS in Quasar Framework SSR via Unescaped Meta Tag Rendering","url":"https://feed.craftedsignal.io/briefs/2026-10-quasar-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Quasar","version":"https://jsonfeed.org/version/1.1"}