Local File Permissions Vulnerability in Quasar Framework Products
CVE-2026-106105
8.4HIGH
What is CVE-2026-106105?
The Quasar Framework's caching mechanism for the @quasar/ssl-certificate utility improperly manages file permissions by storing a combined private key and certificate PEM without applying owner-only filesystem permissions. This oversight allows an attacker with local access to read the cache and replicate the key, leading to the potential impersonation of TLS endpoints in environments that trust the affected certificates. The affected versions also generated CA-capable certificates with unnecessarily broad key usages, raising further security concerns. This vulnerability is addressed in the updated versions of the affected products.
Affected Version(s)
app-vite < 3.3.0
cli < 5.0.4
quasar < 2.23.3
