HTML Attribute Injection in Quasar Framework by Quasar
CVE-2026-106107
What is CVE-2026-106107?
The Quasar Framework, designed for building efficient Vue.js user interfaces, possesses a vulnerability prior to version 3.3.0. In certain SSR and SSG rendering paths, the framework improperly interpolates the ssrContext.nonce value directly into HTML attributes. If an application modifies or sets this value using data controlled by an attacker, it could lead to malicious manipulation of the nonce attribute. This can permit the injection of extraneous attributes or markup into the generated HTML output during both development and production phases. However, note that base64 or base64url nonces, which do not include HTML attribute delimiters, are not susceptible to this issue. This vulnerability has been addressed in the latest release, version 3.3.0.
Affected Version(s)
app-vite < 3.3.0
quasar < 2.23.4
