← Blog · · df00tech

Quasar Framework SSR Meta Rendering Vulnerable to Unescaped XSS Injection (CVE-2026-106102)

breaking ghsa npm CVE-2026-106102

A security advisory published on GitHub (GHSA-pq96-jpmf-w254) discloses a critical cross-site scripting vulnerability in the Quasar Framework's server-side rendering (SSR) meta tag handling, tracked as CVE-2026-106102 with a reported CVSS score of 10.0. According to the advisory, the flaw lives in getHead() and getAttr() inside ui/src/plugins/meta/Meta.js, which serialize data collected from the framework's public useMeta() composable into raw HTML injected directly into the <head> of SSR responses — without any HTML-entity or attribute-quote escaping. The advisory notes this is distinct from the client-side rendering path, which uses DOM APIs that escape automatically and is reportedly not affected.

Why It Matters

This is npm-ecosystem supply chain exposure for any Quasar SSR application. The advisory states that useMeta() is the standard, documented way apps set page titles, descriptions, and other meta content — meaning any application that renders user- or data-influenced text (blog post titles, product names, user display names, CMS fields) through it could be exposed without doing anything unusual. The advisory describes exploitation as not requiring authentication, only the ability to influence text that reaches useMeta(), and claims the impact includes full client-side script execution in the victim site's origin — session/cookie theft, phishing overlays, and account takeover. A public proof-of-concept is referenced in the advisory (poc-public exploit status).

What Defenders Should Watch For

  • Inventory which internet-facing applications use Quasar with SSR enabled, and identify any useMeta() calls that pass through user-, API-, or CMS-controlled strings (titles, descriptions, link/meta attributes).
  • Review deployment logs/WAF data for request bodies or stored content containing sequences like </title>, unescaped ", or <script> in fields that ultimately populate page metadata.
  • Until patched, consider sanitizing any dynamic values before passing them to useMeta(), or front SSR responses with a WAF rule that flags anomalous HTML markup appearing in otherwise plain-text metadata fields.
  • Treat this as a template-injection-style bug for hunting purposes — look for anomalous DOM content appearing in server-rendered <head> output that wasn't present in the original stored data.

This is developing, net-new intel based on a single advisory published today; patch availability and affected version ranges should be confirmed directly from the source before taking remediation action. Full technical details, the referenced proof-of-concept, and the vendor's fix branch are available at the original GHSA advisory.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.