Security: quasarframework/quasar
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Development TLS private keys are cached with overly permissive filesystem permissionsGHSA-fh39-c73x-5pjv published
Jul 29, 2026 by rstoenescuModerate -
App Vite build cleanup can recursively remove unsafe configured output directoriesGHSA-q9mq-245r-4g93 published
Jul 29, 2026 by rstoenescuModerate -
App Vite SSG page output paths can escape the configured distribution directoryGHSA-vhhq-m2gm-rwc9 published
Jul 29, 2026 by rstoenescuModerate -
App Vite SSR and SSG nonce attributes are not safely constrainedGHSA-5m6h-8g35-p3m7 published
Jul 29, 2026 by rstoenescuModerate -
Icon Genie installs vulnerable image-processing dependenciesGHSA-f8wh-5425-35vx published
Jul 28, 2026 by rstoenescuHigh -
SSR/SSG dev error page discloses the full shell environment and its </script> escape is bypassableGHSA-r5mf-4r5x-q78f published
Jul 29, 2026 by rstoenescuModerate -
Super-linear regex backtracking on User-Agent lets one request stall a Quasar SSR serverGHSA-68jq-fhch-4xq4 published
Jul 28, 2026 by rstoenescuHigh -
Prototype Pollution in `extend()` Deep Merge via `__proto__` KeyGHSA-qgrf-j65m-5hh8 published
Jul 21, 2026 by rstoenescuHigh -
Path Traversal / Arbitrary File Write via crafted Icon Genie profileGHSA-wmpw-j6qv-mw88 published
Jul 21, 2026 by rstoenescuHigh -
Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead()GHSA-pq96-jpmf-w254 published
Jul 21, 2026 by rstoenescuCritical