{"id":"CVE-2026-106101","title":"Quasar Framework is a framework for building high-performance Vue.js user interfaces","summary":"Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.32.2, the openURL() utility in ui/src/utils/open-url/open-url.js trusted window.SafariViewController whenever that global existed in an iOS …","severity":"low","cvss":3.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","cwe":["CWE-843"],"vendor":"quasarframework","product":"quasar","affected":["quasar < 2.32.2"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T20:03:40.690","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106101","references":[{"url":"https://github.com/quasarframework/quasar/commit/52d874bf55309dd3656fb02aed033ab025d477ec","label":"security-advisories@github.com"},{"url":"https://github.com/quasarframework/quasar/releases/tag/quasar-v2.32.2","label":"security-advisories@github.com"},{"url":"https://github.com/quasarframework/quasar/security/advisories/GHSA-89vp-x45c-52cq","label":"security-advisories@github.com"},{"url":"https://github.com/quasarframework/quasar/security/advisories/GHSA-89vp-x45c-52cq","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106101"},{"url":"https://github.com/advisories/GHSA-89vp-x45c-52cq"}],"tags":["nvd","cve.org","exploit-available","ghsa","npm"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-06T17:24:41.442349Z"},"ingestedAt":"2026-10-06T18:11:36.223Z","aliases":["GHSA-89vp-x45c-52cq"],"ecosystem":"npm","patched":["quasar 2.32.2"],"slug":"CVE-2026-106101","body":"## Overview\n\nQuasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.32.2, the openURL() utility in ui/src/utils/open-url/open-url.js trusted window.SafariViewController whenever that global existed in an iOS environment. Attacker-controlled HTML rendered by components such as QEditor can create a named SafariViewController element, causing browser named-property resolution to replace the expected native bridge object. A later openURL() call then invokes isAvailable() on the element, throws a TypeError, and disrupts external navigation, login redirects, payment redirects, and other URL-opening workflows. QSelect and QChatMessage HTML-rendering configurations can expose the same trigger when they render attacker-controlled HTML. This issue is fixed in version 2.32.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-106101)\n\nAffected packages:\n\n- `quasar <= 2.32.1`\n\nPatched in:\n\n- `quasar 2.32.2`\n\nSource: https://github.com/advisories/GHSA-89vp-x45c-52cq","depth":"twilight","depthScore":29,"depthScoreParts":{"impact":17.1,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[]}