PatchSiren

quasarframework CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM quasarframework CVE published 2026-08-13

CVE-2026-73647

The Quasar Framework, used for building high-performance Vue.js user interfaces, had a vulnerability in its public extend() utility prior to version 2.22.0. This utility could recursively copy attacker-controlled object keys during deep merges without properly handling the __proto__ property. This could lead to prototype pollution, allowing attackers to write properties to Object.prototype in the same Jav [truncated]