← Back to CVE List
CVE-2026-106107NVD
Vulnerability Summary
Several @quasar/app-vite SSR and SSG renderer paths interpolate `ssrContext.nonce` directly into quoted HTML attributes. An application that derives or overrides the nonce using untrusted data can allow a quote to terminate the nonce attribute and inject additional attributes or markup into generated HTML.
Cryptographically generated base64 or base64url nonces are not directly affected because they do not contain HTML attribute delimiters. Exploitation requires an application to place attacker-controlled or otherwise unsafe data in `ssrContext.nonce`.
The remediation centralizes nonce handling across development SSR/SSG, production SSR, production SSG, critical CSS, store-state scripts, and Vue Devtools. It validates the value as a non-empty base64/base64url CSP nonce and HTML-encodes the attribute value before rendering.
Cryptographically generated base64 or base64url nonces are not directly affected because they do not contain HTML attribute delimiters. Exploitation requires an application to place attacker-controlled or otherwise unsafe data in `ssrContext.nonce`.
The remediation centralizes nonce handling across development SSR/SSG, production SSR, production SSG, critical CSS, store-state scripts, and Vue Devtools. It validates the value as a non-empty base64/base64url CSP nonce and HTML-encodes the attribute value before rendering.
CVSS v4.0 Base Metrics — Score 8.3
Attack VectorNetwork
Attack ComplexityHigh
Attack RequirementsPresent
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)High
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- @quasar/app-vite <= 3.2.0
Not provided by Private for this CVE.
External References
- https://github.com/quasarframework/quasar/security/advisories/GHSA-5m6h-8g35-p3m7
- https://nvd.nist.gov/vuln/detail/CVE-2026-106107
- https://github.com/quasarframework/quasar/commit/91271c38859bec51e154b60c24497a637ce903d7
- https://github.com/quasarframework/quasar/releases/tag/@quasar/app-vite-v3.3.0
- https://github.com/advisories/GHSA-5m6h-8g35-p3m7