PT-2026-106810 · Unknown · Quasar Framework
CVE-2026-106102
·
Published
2026-10-06
·
Updated
2026-10-06
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Quasar Framework versions prior to 2.22.0
Description
The SSR-only
getHead() serializer in ui/src/plugins/meta/Meta.js uses getAttr() to interpolate values provided via useMeta() into title, meta, link, and script markup without proper HTML text or quoted-attribute encoding. The injectServerMeta() function then appends this output to the raw server-rendered response. An attacker capable of influencing dynamic page metadata, such as product names or post titles, can terminate the HTML context and inject executable markup before hydration. Hydration is the process where the client-side JavaScript takes over the static HTML sent by the server to make it interactive.Recommendations
Update to version 2.22.0.
Exploit
Fix
Improper Encoding or Escaping of Output
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Quasar Framework