quasar
npm4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting quasarpage 1 of 1
- CVE-2026-106101LOWCVSS 3.1EG 3.1fixed in 2.32.22026-10-06
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.32.2, the openURL() utility in ui/src/utils/open-url/open-url.js trusted window.SafariViewController whenever that global existed in an iOS en…
- CVE-2026-106102CRITICALCVSS 10.0EG 10.0fixed in 2.22.02026-10-06
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into ti…
- CVE-2026-106104HIGHCVSS 8.7EG 8.7fixed in 2.23.32026-10-06
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.23.3, Platform.parseSSR() passed an unbounded User-Agent request header to getMatch() in ui/src/plugins/platform/Platform.js, whose browser-de…
- CVE-2026-73647MEDIUMCVSS 5.6EG 5.6fixed in 2.22.02026-08-13
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys during extend(true, targ…
Check whether quasar is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for quasar CVEs against the assets you own.
Book a Demo →