Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-73647— Quasar Framework: Prototype pollution in Quasar extend() utility

Quick assessment

Affected
quasarframework quasar
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Quasar 框架是一个用于构建高性能 Vue.js 用户界面的框架。在 2.22.0 版本之前, 中提供的公开 工具函数在执行深度合并(如 )时,会递归复制攻击者可控的对象键,而未拒绝自身的 属性。该合并过程可能会进入原型对象,并将攻击者可控的属性写入同一 JavaScript 进程中的 。如果应用程序将用户可控或部分用户可控的对象传递给 ,当被污染的属性随后被消费时,可能会导致逻辑绕过、不安全的默认选项注入、拒绝服务(DoS)或其他特定于应用程序的影响。该问题已在 2.22.0 版本中得到修复。

CVSS 5.6 · Medium EPSS 0.39% · P31

Possible ATT&CK Techniques 1 AI

T1195.002 · Compromise Software Supply Chain

Affected Version Matrix 1

VendorProduct Version RangeStatus
quasarframework quasar < 2.22.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73647

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Quasar Framework: Prototype pollution in Quasar extend() utility
Source: CVE Program / CVE List V5
Vulnerability Description
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys during extend(true, target, source) deep merges without rejecting an own __proto__ property. The merge could descend into the prototype object and write attacker-controlled properties to Object.prototype in the same JavaScript process. Applications that passed user-controlled or partially user-controlled objects to extend() could experience logic bypass, unsafe default-option injection, denial of service, or other application-specific impact when polluted properties were later consumed. This issue is fixed in version 2.22.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1321
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
quasarframework quasar < 2.22.0 -

II. Public POCs for CVE-2026-73647

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73647

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-73647 (1)

Vendor Advisories for CVE-2026-73647 (1)

Vendor Pages for CVE-2026-73647 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-73647

No comments yet


Leave a comment