CVE-2026-106102Critical· 10.0▾ MidnightQuasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 55 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into title, meta, link, and script markup without HTML text or quoted-attribute encoding. injectServerMeta() appended that output to the raw server-rendered response. An attacker who can influence dynamic page metadata, such as a post title, product name, excerpt, or display name, can terminate the intended HTML context and inject executable markup before hydration. The client-side apply() path is not affected because it uses DOM APIs that encode attributes. This issue is fixed in version 2.22.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106107High· 8.3Quasar Framework is a framework for building high-performance Vue.js user interfaces
CVE-2026-106106High· 7.1Quasar Framework is a framework for building high-performance Vue.js user interfaces
GHSA-3r53-75j5-3g7jMedium· 5.6Quasar: Prototype pollution in the extend() utility
CVE-2026-106104High· 8.7Quasar Framework is a framework for building high-performance Vue.js user interfaces
CVE-2026-106103High· 7.1Quasar Framework is a framework for building high-performance Vue.js user interfaces
CVE-2026-106109Medium· 4.1Quasar Framework is a framework for building high-performance Vue.js user interfaces