CVE-2026-106101
Received Received - Intake

Quasar Framework SafariViewController Named Property Confusion

Vulnerability report for CVE-2026-106101, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.32.2, the openURL() utility in ui/src/utils/open-url/open-url.js trusted window.SafariViewController whenever that global existed in an iOS environment. Attacker-controlled HTML rendered by components such as QEditor can create a named SafariViewController element, causing browser named-property resolution to replace the expected native bridge object. A later openURL() call then invokes isAvailable() on the element, throws a TypeError, and disrupts external navigation, login redirects, payment redirects, and other URL-opening workflows. QSelect and QChatMessage HTML-rendering configurations can expose the same trigger when they render attacker-controlled HTML. This issue is fixed in version 2.32.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
quasarframework quasar < 2.32.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-843 The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Quasar Framework before 2.32.2 has a vulnerability in the openURL() utility where it trusts window.SafariViewController in iOS environments. Attackers can create a named SafariViewController element to replace the native bridge object. This causes openURL() to throw a TypeError, disrupting URL-opening workflows like navigation, login, and payments.

Detection Guidance

This vulnerability is specific to Quasar Framework versions prior to 2.32.2 and involves SafariViewController manipulation. Detection requires checking the installed Quasar Framework version in your project. Run 'npm list quasar' or check your package.json file to verify the version.

Impact Analysis

This vulnerability can disrupt critical workflows such as external navigation, login redirects, and payment redirects. It may also affect applications using QSelect or QChatMessage with attacker-controlled HTML rendering.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR, HIPAA, or similar standards as it primarily affects URL navigation and UI functionality in a web framework. No evidence suggests it leads to data breaches or unauthorized access, which are key concerns for these regulations.

Mitigation Strategies

Upgrade Quasar Framework to version 2.32.2 or later immediately. Update your project dependencies using 'npm update quasar' or by modifying your package.json to specify version 2.32.2 or higher.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106101. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart