PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106106 Quasar Framework CVE debrief

The Quasar Framework's SSR/SSG development error page discloses sensitive information, including environment variables, request headers, and cookies, due to insecure serialization and a bypassable </script> escape. This issue affects @quasar/render-ssr-error and @quasar/app-vite packages. The error page, shown when an SSR or SSG render throws in development, serializes every variable in `process.env`, every request header, and every cookie into the HTTP response. The dev server binds `0.0.0.0` by default, making it accessible to any host that can reach the port. This exposure includes developer's cloud keys, registry tokens, and database URLs from a single unauthenticated GET. The

Vendor
Quasar Framework
Product
@quasar/render-ssr-error
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Developers using Quasar Framework for SSR/SSG development should assess their exposure and prioritize remediation to protect sensitive information. This includes verifying if the Quasar Framework versions in use are affected, updating packages like @quasar/render-ssr-error and @quasar/app-vite to secure versions, and implementing compensating controls. It's crucial for developers to understand the potential impact on their applications and take necessary

Why it matters

CVE-2026-106106 exposes sensitive information and allows script execution in Quasar Framework's SSR/SSG development error page. Developers should verify exposure, prioritize remediation, and implement compensating controls.

  • Sensitive information disclosure
  • Potential script execution in the dev server's origin
  • Exposure of cloud keys, registry tokens, and database URLs

Technical summary

The Quasar Framework's SSR/SSG development error page insecurely serializes sensitive data, including environment variables, request headers, and cookies. The page's </script> escape mechanism can be bypassed, allowing script execution. The issue arises from `renderSSRError()` building the page by splicing a JSON blob into a prebuilt bundle. This JSON blob is generated from `utils/render-ssr-error/src/env.js`, which includes sensitive data. The </script> escape is bypassable due to its ASCII-case-sensitive nature and requirement for a literal `>`, allowing variations like `</SCRIPT>`, `</script >`, and `</script/>` to escape the element and give script execution in the dev server's origin.

Defensive priority

Developers using Quasar Framework for SSR/SSG should verify their exposure, prioritize remediation, and implement compensating controls to protect sensitive information.

Recommended defensive actions

  • Verify exposure by checking if the Quasar Framework versions in use are affected.
  • Update @quasar/render-ssr-error to version 2.2.4 or later.
  • Update @quasar/app-vite to version 3.3.0 or later.
  • Implement compensating controls, such as restricting access to the development server.
  • Monitor for potential exploitation attempts.

Evidence notes

The error page in Quasar CLI for SSR/SSG development exposes sensitive data, including environment variables, request headers, and cookies, due to insecure practices. The </script> escape mechanism can be bypassed using specific closing tags.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106106 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106106

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106106 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106106

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.