Vulnerability GHSA-5m6h-8g35-p3m7

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 hours ago
October 07, 2026 at 04:16 PM UTC
Quasar Framework: App Vite SSR and SSG nonce attributes are not safely constrained
1.0.0-alpha.0 - 3.2.0
1.0.0-alpha.0 - 3.2.0

Summary

Quasar Framework: App Vite SSR and SSG nonce attributes are not safely constrained

Details

Several @quasar/app-vite SSR and SSG renderer paths interpolate ssrContext.nonce directly into quoted HTML attributes. An application that derives or overrides the nonce using untrusted data can allow a quote to terminate the nonce attribute and inject additional attributes or markup into generated HTML.

Cryptographically generated base64 or base64url nonces are not directly affected because they do not contain HTML attribute delimiters. Exploitation requires an application to place attacker-controlled or otherwise unsafe data in ssrContext.nonce.

The remediation centralizes nonce handling across development SSR/SSG, production SSR, production SSG, critical CSS, store-state scripts, and Vue Devtools. It validates the value as a non-empty base64/base64url CSP nonce and HTML-encodes the attribute value before rendering.

Impacted packages

Timeline

Published
2 hours ago
October 07, 2026 at 04:16 PM UTC
Fixed (3.3.0)
2 months ago
July 29, 2026 at 01:37 PM UTC
Last Modified
2 hours ago
October 07, 2026 at 04:30 PM UTC