Quasar Framework CVE-2026-106102 (CVSS 10.0 per CNA): server-side rendered meta tags inserted page metadata without escaping, allowing script injection; fixed in 2.22.0
A CVE record published through GitHub's CNA on 6 October 2026 covers a cross-site scripting flaw in Quasar, the Vue.js user-interface framework. Before 2.22.0, the server-side rendering (SSR) meta plugin built title, meta, link and script tags from values passed to useMeta() without HTML encoding, then added them to the raw server response. If an app puts attacker-influenced text such as a post title, product name, excerpt or display name into page metadata, an attacker can break out of the tag and inject script that runs for every visitor before the page hydrates. Client-side rendering is not affected because it sets attributes through the browser's DOM APIs. The CNA scores it 10.0 (network, no privileges, no user interaction, scope changed), though real impact depends on whether an app feeds user content into useMeta() on SSR pages. The fix shipped in quasar 2.22.0 in July 2026; the current release is 2.34.0. No exploitation has been reported. Primary: Quasar GitHub advisory and CVE record.
- Product
- Quasar Framework (quasar npm package, SSR mode, Meta plugin / useMeta)
- Versions
- quasar before 2.22.0 when using SSR (fixed 2.22.0)
- CVSS
- Critical (CVSS 3.1, GitHub CNA)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N - Exploited in Australia?
- unknown
- Patch to
- Upgrade quasar to 2.22.0 or later (current 2.34.0) and redeploy SSR builds. Until then, escape or strip HTML from any user-supplied text before passing it to useMeta(), and add a Content Security Policy that blocks inline script. Check lockfiles in apps that pin older Quasar versions.
Primary: Quasar — GHSA-pq96-jpmf-w254: XSS via unescaped SSR meta tag rendering in getHead() · Vendor: CVE record — CVE-2026-106102 (published 6 Oct 2026) · CVE: CVE-2026-106102 · Quasar — v2.22.0 release
