Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-106102— Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead()

Quick assessment

Affected
quasarframework quasar
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Quasar 框架是一个用于构建高性能 Vue.js 用户界面的框架。在 2.22.0 版本之前, 中仅服务于服务端渲染(SSR)的 序列化函数使用 将通过 提供的值插入到 、 、 和 标签中,但未对 HTML 文本或带引号的属性值进行编码。 函数随后将该输出直接拼接到原始的服务端渲染响应中。攻击者若能够影响动态页面元数据(例如帖子标题、产品名称、摘要或显示名称),便可终止预期的 HTML 上下文,并在客户端水合(hydration)之前注入可执行的标记。客户端侧的 路径不受此漏洞影响,因为它使用了具有属性编码功能

CVSS 10.0 · Critical

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise

Affected Version Matrix 1

VendorProduct Version RangeStatus
quasarframework quasar < 2.22.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-106102

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead()
Source: CVE Program / CVE List V5
Vulnerability Description
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into title, meta, link, and script markup without HTML text or quoted-attribute encoding. injectServerMeta() appended that output to the raw server-rendered response. An attacker who can influence dynamic page metadata, such as a post title, product name, excerpt, or display name, can terminate the intended HTML context and inject executable markup before hydration. The client-side apply() path is not affected because it uses DOM APIs that encode attributes. This issue is fixed in version 2.22.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
quasarframework quasar < 2.22.0 -

II. Public POCs for CVE-2026-106102

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-106102

请登录查看更多情报信息。

Vendor Pages for CVE-2026-106102 (1)

Other References for CVE-2026-106102 (2)

Same Patch Batch · quasarframework · 2026-10-06 · 8 CVEs total

CVE-2026-106104 8.7 HIGH Quasar Framework: Super-linear regex backtracking on User-Agent lets one request stall a Q
CVE-2026-106105 8.4 HIGH Quasar Framework: Development TLS private keys are cached with overly permissive filesyste
CVE-2026-106107 8.3 HIGH Quasar Framework: App Vite SSR and SSG nonce attributes are not safely constrained
CVE-2026-106103 7.1 HIGH Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Genie profile
CVE-2026-106106 7.1 HIGH Quasar Framework: SSR/SSG dev error page discloses the full shell environment and its </sc
CVE-2026-106109 4.1 MEDIUM Quasar Framework: App Vite build cleanup can recursively remove unsafe configured output d
CVE-2026-106101 3.1 LOW Quasar Framework: DOM Clobbering in Quasar openURL() SafariViewController Integration Caus

IV. Related Vulnerabilities

V. Comments for CVE-2026-106102

No comments yet


Leave a comment