Description
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into title, meta, link, and script markup without HTML text or quoted-attribute encoding. injectServerMeta() appended that output to the raw server-rendered response. An attacker who can influence dynamic page metadata, such as a post title, product name, excerpt, or display name, can terminate the intended HTML context and inject executable markup before hydration. The client-side apply() path is not affected because it uses DOM APIs that encode attributes. This issue is fixed in version 2.22.0.
Published: 2026-10-06
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Stored/Reflected Cross‑Site Scripting via SSR meta tag
Action: Patch
AI Analysis

Impact

The vulnerability arises when the Quasar Framework SSR routine renders meta information without escaping user‑supplied content, allowing an attacker who can influence metadata such as page titles or excerpts to place malicious script tags into the document head. This flaw is a classic XSS weakness that can execute arbitrary JavaScript in the victim’s browser, compromising confidentiality, integrity, and authentication of the web application. The root cause is a failure to perform text and attribute encoding (CWE‑116) combined with the ability to inject script content (CWE‑79).

Affected Systems

All releases of Quasar Framework prior to version 2.22.0 are affected. The flaw exists in the getHead() serializer within ui/src/plugins/meta/Meta.js that processes dynamic metadata supplied through useMeta().

Risk and Exploitability

The vulnerability carries a CVSS score of 10, indicating critical severity. Although no EPSS score is available and the flaw is not listed in the CISA KEV catalog, the likelihood of exploitation is non‑negligible for applications that expose metadata to untrusted or partially trusted input sources. Attackers would target sites where page metadata can be controlled, such as content management systems or social media platforms, to insert malicious code that executes upon user visit. Once executed, the attacker can hijack sessions, exfiltrate data, or redirect users. The risk persists even if the client‑side apply() path is unchanged because the issue manifests in the initial server‑rendered page, which is delivered to the client before front‑end rehydration.

Generated by OpenCVE AI on October 6, 2026 at 19:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Quasar v2.22.0 or later, which applies proper escaping to all metadata output.
  • Validate and HTML‑escape any metadata values before passing them to useMeta, ensuring that no untrusted content can contain script tags or event handlers.
  • Restrict access to the functionality that sets page metadata to privileged users only, and enforce strict input validation on any content that influences title or meta tag values.

Generated by OpenCVE AI on October 6, 2026 at 19:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Quasarframework
Quasarframework quasar
Vendors & Products Quasarframework
Quasarframework quasar

Tue, 06 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into title, meta, link, and script markup without HTML text or quoted-attribute encoding. injectServerMeta() appended that output to the raw server-rendered response. An attacker who can influence dynamic page metadata, such as a post title, product name, excerpt, or display name, can terminate the intended HTML context and inject executable markup before hydration. The client-side apply() path is not affected because it uses DOM APIs that encode attributes. This issue is fixed in version 2.22.0.
Title Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead()
Weaknesses CWE-116
CWE-79
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Quasarframework Quasar
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T17:39:02.751Z

Reserved: 2026-10-06T15:33:55.333Z

Link: CVE-2026-106102

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T17:17:24.270

Modified: 2026-10-06T20:03:40.690

Link: CVE-2026-106102

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T06:00:08Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')