๐Ÿ” CVE Alert

CVE-2026-106101

LOW 3.1

Quasar Framework: DOM Clobbering in Quasar openURL() SafariViewController Integration Causes Client-Side Denial of Service

CVSS Score
3.1
EPSS Score
0.0%
EPSS Percentile
0th

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.32.2, the openURL() utility in ui/src/utils/open-url/open-url.js trusted window.SafariViewController whenever that global existed in an iOS environment. Attacker-controlled HTML rendered by components such as QEditor can create a named SafariViewController element, causing browser named-property resolution to replace the expected native bridge object. A later openURL() call then invokes isAvailable() on the element, throws a TypeError, and disrupts external navigation, login redirects, payment redirects, and other URL-opening workflows. QSelect and QChatMessage HTML-rendering configurations can expose the same trigger when they render attacker-controlled HTML. This issue is fixed in version 2.32.2.

CWE CWE-843
Vendor quasarframework
Product quasar
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for quasarframework quasar

Be the first to know when new low vulnerabilities affecting quasarframework quasar are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Affected Versions

quasarframework / quasar
< 2.32.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/quasarframework/quasar/security/advisories/GHSA-89vp-x45c-52cq github.com: https://github.com/quasarframework/quasar/commit/52d874bf55309dd3656fb02aed033ab025d477ec github.com: https://github.com/quasarframework/quasar/releases/tag/quasar-v2.32.2