PT-2026-106809 · Unknown · Quasar Framework

CVE-2026-106101

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Quasar Framework versions prior to 2.32.2
Description The openURL() utility in ui/src/utils/open-url/open-url.js incorrectly trusts window.SafariViewController in iOS environments. When components like QEditor, QSelect, or QChatMessage render attacker-controlled HTML, a named SafariViewController element can be created. This triggers browser named-property resolution, replacing the native bridge object. Consequently, calling isAvailable() on this element causes a TypeError, which disrupts external navigation, login redirects, and payment redirects.
Recommendations Update to version 2.32.2.

Exploit

Fix

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106101
GHSA-89VP-X45C-52CQ

Affected Products

Quasar Framework