Quasar 框架是一个用于构建高性能 Vue.js 用户界面的框架。在 @quasar/render-ssr-error 2.2.4 和 @quasar/app-vite 3.3.0 版本之前, 中的 函数会利用 中的诊断数据,将 、请求头和 Cookie 序列化为 HTTP 页面,并由 返回。同时,开发服务器默认监听所有网络接口。任何处于同一网络环境中的客户端,如果通过此仅限开发环境使用的错误路径触发了 SSR(服务端渲染)或 SSG(静态站点生成)渲染失败,就可能获取到 Shell 环境中的敏感信息。 该渲染
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| @quasar | app-vite | < 3.3.0 |
affected |
| @quasar | render-ssr-error | < 2.2.4 |
affected |
| quasarframework | quasar | < 2.23.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| quasarframework | quasar | < 2.23.3 | - |
|
| @quasar | render-ssr-error | < 2.2.4 | - |
|
| @quasar | app-vite | < 3.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106102 | 10.0 CRITICAL | Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead() |
| CVE-2026-106104 | 8.7 HIGH | Quasar Framework: Super-linear regex backtracking on User-Agent lets one request stall a Q |
| CVE-2026-106105 | 8.4 HIGH | Quasar Framework: Development TLS private keys are cached with overly permissive filesyste |
| CVE-2026-106107 | 8.3 HIGH | Quasar Framework: App Vite SSR and SSG nonce attributes are not safely constrained |
| CVE-2026-106103 | 7.1 HIGH | Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Genie profile |
| CVE-2026-106109 | 4.1 MEDIUM | Quasar Framework: App Vite build cleanup can recursively remove unsafe configured output d |
| CVE-2026-106101 | 3.1 LOW | Quasar Framework: DOM Clobbering in Quasar openURL() SafariViewController Integration Caus |
No comments yet