CVE-2026-106105
Received Received - Intake

Information Disclosure in Quasar Framework

Vulnerability report for CVE-2026-106105, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/ssl-certificate 2.1.0, @quasar/cli 5.0.4, and @quasar/app-vite 3.3.0, the @quasar/ssl-certificate utility cached a combined private key and certificate PEM without explicitly applying owner-only filesystem permissions. Another local user able to read the cache can copy the key and impersonate a development TLS endpoint in an environment that trusts the certificate. The generated certificate was also CA-capable, carried unnecessarily broad key usages, and encoded the IPv6 loopback address as a DNS subject alternative name. This issue is fixed in @quasar/ssl-certificate 2.1.0, @quasar/cli 5.0.4, and @quasar/app-vite 3.3.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
quasarframework quasar < 2.23.3
@quasar app-vite < 3.3.0
@quasar cli < 5.0.4
@quasar ssl-certificate < 2.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the Quasar Framework caching a private key and certificate PEM file without setting strict filesystem permissions. A local attacker could read this cache, steal the key, and impersonate a development TLS endpoint in trusted environments. The certificate was also overly permissive, acting as a CA with broad key usages and including unnecessary IPv6 loopback addresses.

Detection Guidance

Check for cached SSL certificates in Quasar Framework directories, particularly files in the @quasar/ssl-certificate cache. Look for files with .pem extensions and verify their permissions are restricted to the owner only. Search for files in typical cache locations like ~/.cache/@quasar/ssl-certificate or project-specific cache folders.

Impact Analysis

If you use affected versions of Quasar Framework tools, an attacker with local access could intercept or manipulate TLS traffic by impersonating development endpoints. This could lead to data breaches, unauthorized access to sensitive information, or man-in-the-middle attacks in trusted environments.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized access to sensitive data, which is a direct violation of GDPR's data protection principles and HIPAA's safeguards for protected health information. Organizations may face penalties for failing to protect data integrity and confidentiality.

Mitigation Strategies

Update @quasar/ssl-certificate to version 2.1.0 or later, @quasar/cli to 5.0.4 or later, and @quasar/app-vite to 3.3.0 or later. Remove any cached private keys and certificates from the filesystem to prevent misuse.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106105. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart