Description
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.32.2, the openURL() utility in ui/src/utils/open-url/open-url.js trusted window.SafariViewController whenever that global existed in an iOS environment. Attacker-controlled HTML rendered by components such as QEditor can create a named SafariViewController element, causing browser named-property resolution to replace the expected native bridge object. A later openURL() call then invokes isAvailable() on the element, throws a TypeError, and disrupts external navigation, login redirects, payment redirects, and other URL-opening workflows. QSelect and QChatMessage HTML-rendering configurations can expose the same trigger when they render attacker-controlled HTML. This issue is fixed in version 2.32.2.
Published: 2026-10-06
Score: 3.1 Low
EPSS: n/a
KEV: No
Impact: Client-Side Denial of Service
Action: Apply Patch
AI Analysis

Impact

This vulnerability allows an attacker to trigger a client‑side denial of service by hijacking the SafariViewController integration in Quasar’s openURL() utility. When an attacker’s HTML defines a named SafariViewController element, the browser resolves the element as the native bridge object. Subsequent calls to openURL() invoke isAvailable() on that element, throw a TypeError, and break external navigation, login redirects, payment redirects, and other URL‑opening workflows, effectively halting user interaction.

Affected Systems

Quasar Framework versions prior to 2.32.2 are affected. Components that render attacker‑controlled HTML, such as QEditor, QSelect and QChatMessage, can trigger the flaw. Only users deploying the openURL() feature in an iOS environment where window.SafariViewController is present need to be concerned.

Risk and Exploitability

The CVSS score is 3.1, indicating medium impact and low exploitation complexity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is attacker‑controlled HTML rendered through vulnerable components; as the flaw requires client‑side JavaScript execution, an attacker who can inject malicious markup into the page can exploit it. Given the ease of triggering, organizations should treat it as a low‑to‑medium risk but still patch promptly.

Generated by OpenCVE AI on October 6, 2026 at 19:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Quasar Framework version 2.32.2 or later.
  • Sanitize or validate all HTML content passed to QEditor, QSelect, and QChatMessage to prevent creation of named SafariViewController elements.
  • If upgrading immediately is not possible, temporarily disable SafariViewController usage in openURL() or restrict the function to trusted inputs only.

Generated by OpenCVE AI on October 6, 2026 at 19:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.32.2, the openURL() utility in ui/src/utils/open-url/open-url.js trusted window.SafariViewController whenever that global existed in an iOS environment. Attacker-controlled HTML rendered by components such as QEditor can create a named SafariViewController element, causing browser named-property resolution to replace the expected native bridge object. A later openURL() call then invokes isAvailable() on the element, throws a TypeError, and disrupts external navigation, login redirects, payment redirects, and other URL-opening workflows. QSelect and QChatMessage HTML-rendering configurations can expose the same trigger when they render attacker-controlled HTML. This issue is fixed in version 2.32.2.
Title Quasar Framework: DOM Clobbering in Quasar openURL() SafariViewController Integration Causes Client-Side Denial of Service
Weaknesses CWE-843
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T17:26:21.581Z

Reserved: 2026-10-06T15:33:55.332Z

Link: CVE-2026-106101

cve-icon Vulnrichment

Updated: 2026-10-06T17:25:16.048Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T17:17:24.110

Modified: 2026-10-06T20:03:40.690

Link: CVE-2026-106101

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T19:15:04Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')