AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-106107.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 8.3CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

Several @quasar/app-vite SSR and SSG renderer paths interpolate `ssrContext.nonce` directly into quoted HTML attributes. An application that derives or overrides the nonce using untrusted data can allow a quote to terminate the nonce attribute and inject additional attributes or markup into generated HTML. Cryptographically generated base64 or base64url nonces are not directly affected because they do not contain HTML attribute delimiters. Exploitation requires an application to place attacker-controlled or otherwise unsafe data in `ssrContext.nonce`. The remediation centralizes nonce handling across development SSR/SSG, production SSR, production SSG, critical CSS, store-state scripts, and Vue Devtools. It validates the value as a non-empty base64/base64url CSP nonce and HTML-encodes the attribute value before rendering.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-5m6h-8g35-p3m7

Open original source · Updated Oct 07, 2026

Quasar Framework: App Vite SSR and SSG nonce attributes are not safely constrained

Source severity: HIGH / 8.3

EcosystemPackageAffected rangeFirst patched
npm@quasar/app-vite3.3.0

Original records & references

PUBLISHED 2026-10-07T12:16:03-04:00
MODIFIED 2026-10-07T12:16:03-04:00
INGESTED 2026-10-08T12:05:11-04:00