๐Ÿ” CVE Alert

CVE-2026-106106

UNKNOWN 0.0

Quasar Framework: SSR/SSG dev error page discloses the full shell environment and its </script> escape is bypassable

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/render-ssr-error 2.2.4 and @quasar/app-vite 3.3.0, renderSSRError() in utils/render-ssr-error/src/index.js used diagnostic data from utils/render-ssr-error/src/env.js to serialize process.env, request headers, and cookies into the HTTP page returned by serve.devError(), while the development server listened on all interfaces by default. Any network-adjacent client that reaches an SSR or SSG render failure through this development-only error path can obtain shell environment secrets. The renderer escaped only one exact lowercase script closing-tag spelling, so case variants and valid closing-tag delimiter variants in reflected diagnostic data could terminate the script element and inject markup; executing the injected code in a developer browser additionally requires the payload to accompany that developer's request. This issue is fixed in @quasar/render-ssr-error 2.2.4 and @quasar/app-vite 3.3.0.

CWE CWE-79 CWE-497
Vendor quasarframework
Product quasar
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for quasarframework quasar

Be the first to know when new unknown vulnerabilities affecting quasarframework quasar are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

quasarframework / quasar
< 2.23.3
@quasar / render-ssr-error
< 2.2.4
@quasar / app-vite
< 3.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/quasarframework/quasar/security/advisories/GHSA-r5mf-4r5x-q78f github.com: https://github.com/quasarframework/quasar/commit/61c2bd8a607785fdade72cce20e8faf1de7eee15 github.com: https://github.com/quasarframework/quasar/releases/tag/@quasar/app-vite-v3.3.0
escape is bypassable","description":"UNKNOWN severity (CVSS 0.0). EPSS exploitability: 0.0%. Affects quasarframework quasar. Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/render-ssr-error ","datePublished":"2026-10-06T17:24:07.788Z","dateModified":"2026-10-06T18:22:44.948Z","url":"https://cve-alerts.datmt.com/cve/CVE-2026-106106","keywords":"CVE-2026-106106, UNKNOWN, quasarframework, quasar","publisher":{"@type":"Organization","name":"CVE Alert","url":"https://cve-alerts.datmt.com"}}