MEDIUM
quasarframework
CVE published 2026-08-13
CVE-2026-73647
The Quasar Framework, used for building high-performance Vue.js user interfaces, had a vulnerability in its public extend() utility prior to version 2.22.0. This utility could recursively copy attacker-controlled object keys during deep merges without properly handling the __proto__ property. This could lead to prototype pollution, allowing attackers to write properties to Object.prototype in the same Jav [truncated]