HTML Attribute Injection in Quasar Framework by Quasar
CVE-2026-106107

8.3HIGH

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106107?

The Quasar Framework, designed for building efficient Vue.js user interfaces, possesses a vulnerability prior to version 3.3.0. In certain SSR and SSG rendering paths, the framework improperly interpolates the ssrContext.nonce value directly into HTML attributes. If an application modifies or sets this value using data controlled by an attacker, it could lead to malicious manipulation of the nonce attribute. This can permit the injection of extraneous attributes or markup into the generated HTML output during both development and production phases. However, note that base64 or base64url nonces, which do not include HTML attribute delimiters, are not susceptible to this issue. This vulnerability has been addressed in the latest release, version 3.3.0.

Affected Version(s)

app-vite < 3.3.0

quasar < 2.23.4

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.