CVE-2026-106107
Last modified
CVE-2026-106107 is a high-severity vulnerability rated 8.3/10 on the CVSS scale. Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 3.3.0, several @quasar/app-vite SSR and SSG rendering paths interpolated ssrContext.nonce directly into quoted HTML attributes.
Description
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 3.3.0, several @quasar/app-vite SSR and SSG rendering paths interpolated ssrContext.nonce directly into quoted HTML attributes. An application that derives or overrides this value with attacker-controlled data can allow a quote to terminate the nonce attribute and inject additional attributes or markup into generated HTML across development and production SSR or SSG output. Cryptographically generated base64 or base64url nonces are not affected because they lack HTML attribute delimiters. This issue is fixed in version 3.3.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| quasarframework | quasar | < 2.23.4 |
| @quasar | app-vite | < 3.3.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-106107?
How severe is CVE-2026-106107?
How do I fix CVE-2026-106107?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-106101Quasar Framework is a framework for building high-performanc…3.1
- CVE-2026-106102Quasar Framework is a framework for building high-performanc…10
- CVE-2026-106103Quasar Framework is a framework for building high-performanc…7.1
- CVE-2026-106104Quasar Framework is a framework for building high-performanc…8.7
- CVE-2026-106105Quasar Framework is a framework for building high-performanc…8.4
- CVE-2026-106106Quasar Framework is a framework for building high-performanc…7.1
- CVE-2026-106109Quasar Framework is a framework for building high-performanc…4.1
- CVE-2026-10611An authentication bypass vulnerability exists in MISP when L…10
- CVE-2026-106110ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2,…7.5
- CVE-2026-106111ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2,…5.9
- CVE-2026-106112ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2,…7.5
- CVE-2026-106113ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2,…7.5
Are you affected by CVE-2026-106107?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
