Quasar 框架是一个用于构建高性能 Vue.js 用户界面的框架。在 2.22.0 版本之前, 中仅服务于服务端渲染(SSR)的 序列化函数使用 将通过 提供的值插入到 、 、 和 标签中,但未对 HTML 文本或带引号的属性值进行编码。 函数随后将该输出直接拼接到原始的服务端渲染响应中。攻击者若能够影响动态页面元数据(例如帖子标题、产品名称、摘要或显示名称),便可终止预期的 HTML 上下文,并在客户端水合(hydration)之前注入可执行的标记。客户端侧的 路径不受此漏洞影响,因为它使用了具有属性编码功能
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| quasarframework | quasar | < 2.22.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| quasarframework | quasar | < 2.22.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106104 | 8.7 HIGH | Quasar Framework: Super-linear regex backtracking on User-Agent lets one request stall a Q |
| CVE-2026-106105 | 8.4 HIGH | Quasar Framework: Development TLS private keys are cached with overly permissive filesyste |
| CVE-2026-106107 | 8.3 HIGH | Quasar Framework: App Vite SSR and SSG nonce attributes are not safely constrained |
| CVE-2026-106103 | 7.1 HIGH | Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Genie profile |
| CVE-2026-106106 | 7.1 HIGH | Quasar Framework: SSR/SSG dev error page discloses the full shell environment and its </sc |
| CVE-2026-106109 | 4.1 MEDIUM | Quasar Framework: App Vite build cleanup can recursively remove unsafe configured output d |
| CVE-2026-106101 | 3.1 LOW | Quasar Framework: DOM Clobbering in Quasar openURL() SafariViewController Integration Caus |
No comments yet