CRITICAL
10.0 CVE-2026-106102 Published 6 Oct 2026
Quasar Framework SSR Metadata XSS Vulnerability
Worried this affects your website?
Quasar Framework, a Vue.js UI framework, has patched an SSR metadata injection vulnerability affecting versions before 2.22.0.
The SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js interpolates values supplied through useMeta() into title, meta, link, and script markup without HTML text or quoted-attribute encoding. injectServerMeta() then appends that output to the raw server-rendered response.
- Affected versions: prior to 2.22.0
- Attack vector: an attacker who can influence dynamic page metadata, such as a post title, product name, excerpt, or display name
- Impact: the attacker can terminate the intended HTML context and inject executable markup before hydration
- Not affected: the client-side apply() path, which uses DOM APIs that encode attributes
- Fixed in: version 2.22.0
Reference: CVE-2026-106102 on NVD
← Back to Security News