CVE-2026-106107: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in quasarframework quasar
Description
Quasar Framework versions prior to 3.3.0 contain a cross-site scripting (XSS) vulnerability due to improper neutralization of input during server-side rendering (SSR) and static site generation (SSG). Specifically, the ssrContext.nonce value is interpolated directly into quoted HTML attributes, allowing an attacker who can control or override this value to inject malicious HTML or attributes. This vulnerability is fixed in version 3.3.0.
CVSS v4.0
Score 8.3high
Affected software
quasarframework
quasar
@quasar
app-vite
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Quasar Framework, used for building Vue.js user interfaces, had a vulnerability in versions before 3.3.0 where several SSR and SSG rendering paths interpolated the ssrContext.nonce value directly into quoted HTML attributes without proper sanitization. If an application allows attacker-controlled input to influence this nonce value, it can lead to injection of additional attributes or markup, resulting in cross-site scripting (CWE-79). Cryptographically generated base64 or base64url nonces are not affected due to the absence of HTML attribute delimiters. The issue is resolved in Quasar Framework version 3.3.0.
Potential Impact
An attacker who can influence or override the ssrContext.nonce value in affected Quasar Framework versions can inject arbitrary HTML or attributes into server-rendered pages, leading to cross-site scripting attacks. This can compromise the integrity of the web page and potentially lead to client-side code execution. The vulnerability affects both development and production SSR or SSG outputs. However, cryptographically generated nonces using base64 or base64url are not vulnerable.
Mitigation Recommendations
Upgrade Quasar Framework to version 3.3.0 or later, where this vulnerability is fixed. Applications should ensure that the ssrContext.nonce value is not derived from or overridden by attacker-controlled input. No other mitigations are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-06T15:33:55.333Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac534982cdf04f656cc6bb1
Added to database: 10/06/2026, 17:49:12 UTC
Last enriched: 10/06/2026, 18:03:15 UTC
Last updated: 10/06/2026, 18:08:21 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.