CRITICAL 10.0 CVE-2026-106102 Published 6 Oct 2026

Quasar Framework SSR Metadata XSS Vulnerability

Worried this affects your website?

Quasar Framework, a Vue.js UI framework, has patched an SSR metadata injection vulnerability affecting versions before 2.22.0.

The SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js interpolates values supplied through useMeta() into title, meta, link, and script markup without HTML text or quoted-attribute encoding. injectServerMeta() then appends that output to the raw server-rendered response.

  • Affected versions: prior to 2.22.0
  • Attack vector: an attacker who can influence dynamic page metadata, such as a post title, product name, excerpt, or display name
  • Impact: the attacker can terminate the intended HTML context and inject executable markup before hydration
  • Not affected: the client-side apply() path, which uses DOM APIs that encode attributes
  • Fixed in: version 2.22.0

Reference: CVE-2026-106102 on NVD

← Back to Security News