๐Ÿ” CVE Alert

CVE-2026-106102

CRITICAL 10.0

Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead()

CVSS Score
10.0
EPSS Score
0.0%
EPSS Percentile
0th

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into title, meta, link, and script markup without HTML text or quoted-attribute encoding. injectServerMeta() appended that output to the raw server-rendered response. An attacker who can influence dynamic page metadata, such as a post title, product name, excerpt, or display name, can terminate the intended HTML context and inject executable markup before hydration. The client-side apply() path is not affected because it uses DOM APIs that encode attributes. This issue is fixed in version 2.22.0.

CWE CWE-79 CWE-116
Vendor quasarframework
Product quasar
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for quasarframework quasar

Be the first to know when new critical vulnerabilities affecting quasarframework quasar are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

quasarframework / quasar
< 2.22.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/quasarframework/quasar/security/advisories/GHSA-pq96-jpmf-w254 github.com: https://github.com/quasarframework/quasar/commit/11505afe5b5218f2c468f130181815b898fd1e40 github.com: https://github.com/quasarframework/quasar/releases/tag/quasar-v2.22.0