PT-2026-106824 · Npm · @Quasar/Render-Ssr-Error+1

CVE-2026-106106

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v4.0

7.1

High

VectorAV:A/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions @quasar/render-ssr-error versions prior to 2.2.4 @quasar/app-vite versions prior to 3.3.0
Description The renderSSRError() function in utils/render-ssr-error/src/index.js serializes process.env, request headers, and cookies into the HTTP page returned by serve.devError(). Because the development server listens on all interfaces by default, a network-adjacent client triggering a Server-Side Rendering (SSR) or Static Site Generation (SSG) failure can access shell environment secrets. Additionally, the renderer only escapes a specific lowercase script closing-tag, allowing case variants or other valid closing-tag delimiters in the diagnostic data to terminate the script element and inject markup. Executing this injected code requires the payload to be part of the developer's request.
Recommendations Update @quasar/render-ssr-error to version 2.2.4 or later. Update @quasar/app-vite to version 3.3.0 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106106
GHSA-R5MF-4R5X-Q78F

Affected Products

@Quasar/App-Vite
@Quasar/Render-Ssr-Error