Local File Permissions Vulnerability in Quasar Framework Products
CVE-2026-106105

8.4HIGH

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106105?

The Quasar Framework's caching mechanism for the @quasar/ssl-certificate utility improperly manages file permissions by storing a combined private key and certificate PEM without applying owner-only filesystem permissions. This oversight allows an attacker with local access to read the cache and replicate the key, leading to the potential impersonation of TLS endpoints in environments that trust the affected certificates. The affected versions also generated CA-capable certificates with unnecessarily broad key usages, raising further security concerns. This vulnerability is addressed in the updated versions of the affected products.

Affected Version(s)

app-vite < 3.3.0

cli < 5.0.4

quasar < 2.23.3

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.