AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-106102.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSCRITICAL / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

## Vulnerability Details **File**: `ui/src/utils/meta/Meta.js` — actually `ui/src/plugins/meta/Meta.js` (lines 149-176: `getAttr()` and `getHead()`) **Sink**: `injectServerMeta()` (same file) → `ctx.headTags += getHead(data)`, interpolated verbatim into the raw HTTP response `` by the production SSR template (`app-vite/templates/entry/ssr-prod-webserver.js` + `app-vite/lib/plugins/vite.html.js`) **Entry point**: the public `useMeta()` composable (`ui/src/composables/use-meta/use-meta.js`) — the single documented way apps set page title/meta/link/script tags ### Root Cause `getHead()` is Quasar's SSR-only serializer that turns the meta/link/script/title data collected from every `useMeta()` call into a literal HTML string, using plain template-literal interpolation with **zero HTML-entity escaping and zero attribute-quote escaping**: ```js function getAttr(seed) { return att => { const val = seed[att] return att + (val !== true && val !== void 0 ? `="${val}"` : '') } } function getHead(meta) { let output = '' if (meta.title) { output += `${meta.title}` } ... } ``` Contrast this with the client-side equivalent, `apply()` (same file, used only in the browser post-hydration), which bui

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-pq96-jpmf-w254

Open original source · Updated Oct 07, 2026

Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead()

Source severity: CRITICAL / 0

EcosystemPackageAffected rangeFirst patched
npmquasar< 2.22.02.22.0

Original records & references

PUBLISHED 2026-10-07T12:14:22-04:00
MODIFIED 2026-10-07T12:14:23-04:00
INGESTED 2026-10-08T12:05:11-04:00