PT-2026-106824 · Npm · @Quasar/Render-Ssr-Error+1
CVE-2026-106106
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v4.0
7.1
High
| Vector | AV:A/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
@quasar/render-ssr-error versions prior to 2.2.4
@quasar/app-vite versions prior to 3.3.0
Description
The
renderSSRError() function in utils/render-ssr-error/src/index.js serializes process.env, request headers, and cookies into the HTTP page returned by serve.devError(). Because the development server listens on all interfaces by default, a network-adjacent client triggering a Server-Side Rendering (SSR) or Static Site Generation (SSG) failure can access shell environment secrets. Additionally, the renderer only escapes a specific lowercase script closing-tag, allowing case variants or other valid closing-tag delimiters in the diagnostic data to terminate the script element and inject markup. Executing this injected code requires the payload to be part of the developer's request.Recommendations
Update @quasar/render-ssr-error to version 2.2.4 or later.
Update @quasar/app-vite to version 3.3.0 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Quasar/App-Vite
@Quasar/Render-Ssr-Error