CVE-2026-106102

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into title, meta, link, and script markup without HTML text or quoted-attribute encoding. injectServerMeta() appended that output to the raw server-rendered response. An attacker who can influence dynamic page metadata, such as a post title, product name, excerpt, or display name, can terminate the intended HTML context and inject executable markup before hydration. The client-side apply() path is not affected because it uses DOM APIs that encode attributes. This issue is fixed in version 2.22.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-116

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 3 mentions (2026-10-07); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-10-07: 3Mentions · 2026-10-08: 110-0710-08
Referenced assets2 URLs
Full discourse4 posts
  • ExploitGrid@exploitgrid

    #ExploitGrid Daily #Digest 🚨 Top CVEs: CVE-2026-105484 (CVSS: 10) totolink CVE-2026-105857 (CVSS: 10) payloadcms CVE-2026-106102 (CVSS: 10) quasarframework CVE-2026-32579 (CVSS: 10) CVE-2026-39770 (CVSS: 10) ..🧵👇

    10010157
    370 followersView on X
  • ExploitGrid@exploitgrid

    🟠 HIGH PRIORITY (all CVSS 10) ├ CVE-2026-105484 — TOTOLINK X6000R · OS command injection (firmware upload) ├ CVE-2026-105857 — Payload CMS · RCE in Form Builder ├ CVE-2026-106102 — Quasar Framework · Stored/reflected XSS (SSR meta tag)

    1000038
    370 followersView on X
  • ExploitGrid@exploitgrid

    [CVE] CVE-2026-106102 [HIGH PRIORITY] CVSS: 10 | Vendor: #quasarframework #Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering i... 🔗 https://exploitgrid.net/cve/CVE-2026-106102

    1000030
    370 followersView on X
  • The Hacker Wire@TheHackerWire

    🚨 CVE-2026-106102 (CVSS 10.0 Critical) Unescaped SSR meta tag rendering in Quasar Framework allows unauthenticated remote attackers to execute malicious scripts via stored and reflected XSS. https://www.thehackerwire.com/vulnerability/CVE-2026-106102/ https://t.co/zMV73WsPVy

    0000023
    176 followersView on X

Explore more