The `@quasar/ssl-certificate` development utility in the Quasar Framework caches a combined PEM containing a generated private key and certificate with overly permissive filesystem permissions. This allows other local users to potentially read and reuse the private key, impersonating a development TLS endpoint. The generated certificate is unnecessarily CA-capable with broad key usages beyond localhost HT [truncated]
The Quasar Framework's SSR/SSG development error page discloses sensitive information, including environment variables, request headers, and cookies, due to insecure serialization and a bypassable </script> escape. This issue affects @quasar/render-ssr-error and @quasar/app-vite packages. The error page, shown when an SSR or SSG render throws in development, serializes every variable in `process.env`, eve [truncated]
The CVE record was published on 2026-10-07T16:14:35.000Z and has not been modified since then. The NVD entry is currently null. This vulnerability affects Quasar Framework applications using @quasar/app-vite, potentially leading to data loss if the configured build.distDir targets sensitive directories. Defenders should assess exposure and verify build configurations to prevent data loss. The vulnerabilit [truncated]