@quasar/app-vite, HTML Injection / XSS, CVE-2026-106107 (Medium) -DC-Oct2026-2822

Listen to this Post

The vulnerability stems from improper neutralization of user-supplied data during server-side rendering (SSR) and static site generation (SSG) in @quasar/app-vite. Specifically, several rendering code paths directly interpolate the `ssrContext.nonce` property into quoted HTML tag attributes without prior escaping or validation.
When an application derives or overrides the `ssrContext.nonce` value based on untrusted request data (such as HTTP headers or URL parameters), an attacker can inject quotation marks (e.g., "). This allows the attacker to break out of the intended HTML attribute context. Consequently, additional arbitrary HTML attributes or malicious markup (such as event handlers or `

Scroll to Top