CVE-2026-106102
Received Received - Intake

Quasar Framework SSR Meta Injection Vulnerability

Vulnerability report for CVE-2026-106102, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into title, meta, link, and script markup without HTML text or quoted-attribute encoding. injectServerMeta() appended that output to the raw server-rendered response. An attacker who can influence dynamic page metadata, such as a post title, product name, excerpt, or display name, can terminate the intended HTML context and inject executable markup before hydration. The client-side apply() path is not affected because it uses DOM APIs that encode attributes. This issue is fixed in version 2.22.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
quasarframework quasar < 2.22.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-116 The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Quasar Framework before 2.22.0 has a vulnerability in its SSR-only getHead() serializer. It interpolates user-supplied values into HTML markup without proper encoding, allowing attackers to inject executable markup by influencing dynamic page metadata like post titles or product names.

Detection Guidance

This vulnerability can be detected by checking the Quasar Framework version in use. If your application uses Quasar Framework versions prior to 2.22.0, it is vulnerable. Inspect package.json or dependency files for the Quasar version.

Impact Analysis

An attacker could exploit this to inject malicious scripts or markup into server-rendered pages, potentially leading to cross-site scripting (XSS) attacks, data theft, or unauthorized actions on behalf of users.

Compliance Impact

This vulnerability could lead to data breaches or unauthorized access, violating GDPR's integrity and confidentiality requirements and HIPAA's safeguards for protected health information, potentially resulting in legal penalties and reputational damage.

Mitigation Strategies

Upgrade Quasar Framework to version 2.22.0 or later immediately. Review and sanitize any dynamic metadata inputs like post titles or product names to prevent injection. Monitor server-rendered responses for unexpected markup.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106102. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart