PatchSiren cyber security CVE debrief
CVE-2026-106101 quasarframework CVE debrief
A DOM Clobbering vulnerability exists in Quasar's `openURL()` utility when handling the iOS `SafariViewController` bridge. The vulnerable implementation only checks whether `window.SafariViewController` exists before invoking it as a native bridge object. An attacker who can inject HTML content containing a named element such as `<a id='SafariViewController'>` can cause the browser to expose that element as `window.SafariViewController`. When `openURL()` is later called in an iOS environment, Quasar incorrectly treats the DOM element as the native bridge object and attempts to invoke bridge methods that do not exist, resulting in a TypeError. This can cause client-side denial of service and break navigation-related workflows in Quasar applications.
- Vendor
- quasarframework
- Product
- quasar
- CVSS
- LOW 3.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Quasar applications, especially those that handle user-inputted HTML content, should assess the potential impact of this vulnerability on navigation-related workflows and prioritize verification and remediation efforts.
Why it matters
This vulnerability allows an attacker to cause a client-side denial of service in Quasar applications by exploiting the `openURL()` utility's handling of the iOS `SafariViewController` bridge. Defenders should prioritize verifying the presence of this vulnerability and assessing its potential impact on navigation-related workflows.
- Client-side denial of service attacks are possible
- Navigation-related workflows in Quasar applications may be disrupted
- Verification of vulnerability presence and impact is necessary
- Remediation requires updating to Quasar version 2.32.2 or later
Technical summary
The vulnerable implementation of Quasar's `openURL()` utility checks whether `window.SafariViewController` exists before invoking it as a native bridge object. An attacker who can inject HTML content containing a named element such as `<a id='SafariViewController'>` can cause the browser to expose that element as `window.SafariViewController`. When `openURL()` is later called in an iOS environment, Quasar incorrectly treats the DOM element as the native bridge object and attempts to invoke bridge methods that do not exist, resulting in a TypeError.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in Quasar applications, especially those that handle user-inputted HTML content, and assess the potential impact on navigation-related workflows.
Recommended defensive actions
- Verify the presence of this vulnerability in Quasar applications
- Assess the potential impact on navigation-related workflows
- Update to Quasar version 2.32.2 or later
- Monitor for potential client-side denial of service attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability is confirmed in Quasar versions up to 2.32.1. The fix is available in Quasar version 2.32.2. The CVE Program and NVD provide official records of this vulnerability. Defenders should verify the presence of this vulnerability in Quasar applications, especially those that handle user-inputted HTML content, and assess the potential impact on navigation-related workflows. Evidence is limited to public sources and may not be comprehensive. Further verification is necessary to ensure accurate risk assessment.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106101 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106101
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106101 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106101
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Quasar Framework: DOM Clobbering in Quasar openURL() SafariViewController Integration Causes Cli
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-89vp-x45c-52cq.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/quasarframework/quasar/security/advisories/GHSA-89vp-x45c-52cq
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/quasarframework/quasar/commit/52d874bf55309dd3656fb02aed033ab025d477ec
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/quasarframework/quasar
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/quasarframework/quasar/releases/tag/quasar-v2.32.2
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.