PT-2026-106825 · Unknown · Quasar Framework

CVE-2026-106107

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v4.0

8.3

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Quasar Framework versions prior to 3.3.0
Description Several @quasar/app-vite Server-Side Rendering (SSR) and Static Site Generation (SSG) rendering paths interpolate the ssrContext.nonce variable directly into quoted HTML attributes. If an application derives or overrides this value using attacker-controlled data, a quote character can be used to terminate the nonce attribute, enabling the injection of additional attributes or markup into the generated HTML for both development and production environments. Cryptographically generated base64 or base64url nonces are not affected as they do not contain HTML attribute delimiters.
Recommendations Update Quasar Framework to version 3.3.0.

Exploit

Fix

Improper Encoding or Escaping of Output

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106107
GHSA-5M6H-8G35-P3M7

Affected Products

Quasar Framework