Impact
The vulnerability arises when the Quasar Framework SSR routine renders meta information without escaping user‑supplied content, allowing an attacker who can influence metadata such as page titles or excerpts to place malicious script tags into the document head. This flaw is a classic XSS weakness that can execute arbitrary JavaScript in the victim’s browser, compromising confidentiality, integrity, and authentication of the web application. The root cause is a failure to perform text and attribute encoding (CWE‑116) combined with the ability to inject script content (CWE‑79).
Affected Systems
All releases of Quasar Framework prior to version 2.22.0 are affected. The flaw exists in the getHead() serializer within ui/src/plugins/meta/Meta.js that processes dynamic metadata supplied through useMeta().
Risk and Exploitability
The vulnerability carries a CVSS score of 10, indicating critical severity. Although no EPSS score is available and the flaw is not listed in the CISA KEV catalog, the likelihood of exploitation is non‑negligible for applications that expose metadata to untrusted or partially trusted input sources. Attackers would target sites where page metadata can be controlled, such as content management systems or social media platforms, to insert malicious code that executes upon user visit. Once executed, the attacker can hijack sessions, exfiltrate data, or redirect users. The risk persists even if the client‑side apply() path is unchanged because the issue manifests in the initial server‑rendered page, which is delivered to the client before front‑end rehydration.
OpenCVE Enrichment