CVE-2026-106107
Received Received - Intake

Cross-Site Scripting in Quasar Framework SSR/SSG

Vulnerability report for CVE-2026-106107, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 3.3.0, several @quasar/app-vite SSR and SSG rendering paths interpolated ssrContext.nonce directly into quoted HTML attributes. An application that derives or overrides this value with attacker-controlled data can allow a quote to terminate the nonce attribute and inject additional attributes or markup into generated HTML across development and production SSR or SSG output. Cryptographically generated base64 or base64url nonces are not affected because they lack HTML attribute delimiters. This issue is fixed in version 3.3.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
quasarframework quasar < 2.23.4
@quasar app-vite < 3.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-116 The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Quasar Framework versions before 3.3.0 have a vulnerability where the server-side rendering (SSR) and static site generation (SSG) paths directly interpolate the nonce value from ssrContext into HTML attributes without proper sanitization. This allows attackers to inject additional attributes or markup by manipulating the nonce value if it is derived from untrusted data.

Detection Guidance

To detect this vulnerability, inspect Quasar Framework applications using versions prior to 3.3.0 for improper nonce interpolation in SSR/SSG rendering paths. Check HTML output for nonces derived from untrusted sources or containing quote characters that could allow attribute injection.

Impact Analysis

If you use Quasar Framework versions before 3.3.0 and the nonce value is controlled by attacker-controlled data, an attacker could inject malicious attributes or markup into the generated HTML. This could lead to cross-site scripting (XSS) attacks, defacement, or theft of sensitive data.

Compliance Impact

This vulnerability could lead to data breaches or unauthorized access, which may violate GDPR's data protection requirements or HIPAA's security rules. Non-compliance with these regulations can result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Upgrade Quasar Framework to version 3.3.0 or later to address the vulnerability in SSR and SSG rendering paths.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106107. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart