CVE-2026-106106
Received Received - Intake

Information Disclosure in Quasar Framework SSR

Vulnerability report for CVE-2026-106106, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/render-ssr-error 2.2.4 and @quasar/app-vite 3.3.0, renderSSRError() in utils/render-ssr-error/src/index.js used diagnostic data from utils/render-ssr-error/src/env.js to serialize process.env, request headers, and cookies into the HTTP page returned by serve.devError(), while the development server listened on all interfaces by default. Any network-adjacent client that reaches an SSR or SSG render failure through this development-only error path can obtain shell environment secrets. The renderer escaped only one exact lowercase script closing-tag spelling, so case variants and valid closing-tag delimiter variants in reflected diagnostic data could terminate the script element and inject markup; executing the injected code in a developer browser additionally requires the payload to accompany that developer's request. This issue is fixed in @quasar/render-ssr-error 2.2.4 and @quasar/app-vite 3.3.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
quasarframework quasar < 2.23.3
@quasar render-ssr-error < 2.2.4
@quasar app-vite < 3.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-497 The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Quasar Framework, a Vue.js UI framework. It involves the renderSSRError() function in specific versions of @quasar/render-ssr-error and @quasar/app-vite. The function exposes sensitive shell environment secrets, request headers, and cookies in HTTP error pages during SSR or SSG render failures. The issue arises because the development server listens on all interfaces by default, allowing network-adjacent clients to access these secrets.

Detection Guidance

This vulnerability is specific to Quasar Framework's development server and requires checking for outdated versions of @quasar/render-ssr-error (< 2.2.4) and @quasar/app-vite (< 3.3.0). No direct network or system commands are provided in the CVE details to detect this issue.

Impact Analysis

If you use affected versions of Quasar Framework, an attacker on the same network could exploit this to steal sensitive environment variables, request headers, or cookies. This could lead to unauthorized access to systems, data breaches, or further attacks on your development environment. The risk is higher in shared or untrusted networks.

Compliance Impact

This vulnerability could lead to exposure of personal or sensitive data, violating GDPR and HIPAA requirements for data protection. Organizations may face legal penalties, reputational damage, and loss of trust due to non-compliance with these regulations.

Mitigation Strategies

Update @quasar/render-ssr-error to version 2.2.4 or later and @quasar/app-vite to version 3.3.0 or later to fix the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106106. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart