PatchSiren cyber security CVE debrief
CVE-2026-106106 Quasar Framework CVE debrief
The Quasar Framework's SSR/SSG development error page discloses sensitive information, including environment variables, request headers, and cookies, due to insecure serialization and a bypassable </script> escape. This issue affects @quasar/render-ssr-error and @quasar/app-vite packages. The error page, shown when an SSR or SSG render throws in development, serializes every variable in `process.env`, every request header, and every cookie into the HTTP response. The dev server binds `0.0.0.0` by default, making it accessible to any host that can reach the port. This exposure includes developer's cloud keys, registry tokens, and database URLs from a single unauthenticated GET. The
- Vendor
- Quasar Framework
- Product
- @quasar/render-ssr-error
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Developers using Quasar Framework for SSR/SSG development should assess their exposure and prioritize remediation to protect sensitive information. This includes verifying if the Quasar Framework versions in use are affected, updating packages like @quasar/render-ssr-error and @quasar/app-vite to secure versions, and implementing compensating controls. It's crucial for developers to understand the potential impact on their applications and take necessary
Why it matters
CVE-2026-106106 exposes sensitive information and allows script execution in Quasar Framework's SSR/SSG development error page. Developers should verify exposure, prioritize remediation, and implement compensating controls.
- Sensitive information disclosure
- Potential script execution in the dev server's origin
- Exposure of cloud keys, registry tokens, and database URLs
Technical summary
The Quasar Framework's SSR/SSG development error page insecurely serializes sensitive data, including environment variables, request headers, and cookies. The page's </script> escape mechanism can be bypassed, allowing script execution. The issue arises from `renderSSRError()` building the page by splicing a JSON blob into a prebuilt bundle. This JSON blob is generated from `utils/render-ssr-error/src/env.js`, which includes sensitive data. The </script> escape is bypassable due to its ASCII-case-sensitive nature and requirement for a literal `>`, allowing variations like `</SCRIPT>`, `</script >`, and `</script/>` to escape the element and give script execution in the dev server's origin.
Defensive priority
Developers using Quasar Framework for SSR/SSG should verify their exposure, prioritize remediation, and implement compensating controls to protect sensitive information.
Recommended defensive actions
- Verify exposure by checking if the Quasar Framework versions in use are affected.
- Update @quasar/render-ssr-error to version 2.2.4 or later.
- Update @quasar/app-vite to version 3.3.0 or later.
- Implement compensating controls, such as restricting access to the development server.
- Monitor for potential exploitation attempts.
Evidence notes
The error page in Quasar CLI for SSR/SSG development exposes sensitive data, including environment variables, request headers, and cookies, due to insecure practices. The </script> escape mechanism can be bypassed using specific closing tags.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106106 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106106
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106106 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106106
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Quasar Framework: SSR/SSG dev error page discloses the full shell environment and its </script>
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-r5mf-4r5x-q78f.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/quasarframework/quasar/security/advisories/GHSA-r5mf-4r5x-q78f
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/quasarframework/quasar/commit/61c2bd8a607785fdade72cce20e8faf1de7eee15
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/quasarframework/quasar
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/quasarframework/quasar/releases/tag/@quasar/app-vite-v3.3.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.