PT-2026-106810 · Unknown · Quasar Framework

CVE-2026-106102

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Quasar Framework versions prior to 2.22.0
Description The SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js uses getAttr() to interpolate values provided via useMeta() into title, meta, link, and script markup without proper HTML text or quoted-attribute encoding. The injectServerMeta() function then appends this output to the raw server-rendered response. An attacker capable of influencing dynamic page metadata, such as product names or post titles, can terminate the HTML context and inject executable markup before hydration. Hydration is the process where the client-side JavaScript takes over the static HTML sent by the server to make it interactive.
Recommendations Update to version 2.22.0.

Exploit

Fix

Improper Encoding or Escaping of Output

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106102
GHSA-PQ96-JPMF-W254

Affected Products

Quasar Framework