CVE-2026-106105: fallo de gravedad alta en quasarframework quasar
Quasar Framework: Development TLS private keys are cached with overly permissive filesystem permissions
Publicada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.4epss 0.1%
probabilidad de explotación
0.1%top 100% de las CVE
explotación observada
noninguna fuente lo reporta
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/ssl-certificate 2.1.0, @quasar/cli 5.0.4, and @quasar/app-vite 3.3.0, the @quasar/ssl-certificate utility cached a combined private key and certificate PEM without explicitly applying owner-only filesystem permissions. Another local user able to read the cache can copy the key and impersonate a development TLS endpoint in an environment that trusts the certificate. The generated certificate was also CA-capable, carried unnecessarily broad key usages, and encoded the IPv6 loopback address as a DNS subject alternative name. This issue is fixed in @quasar/ssl-certificate 2.1.0, @quasar/cli 5.0.4, and @quasar/app-vite 3.3.0.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVEs relacionadas — quasarframework quasar
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-106106HIGHQuasar Framework: SSR/SSG dev error page discloses the full shell environment and its </script> escape is bypassableEPSS 0.3%CVE-2026-106107HIGHQuasar Framework: App Vite SSR and SSG nonce attributes are not safely constrainedEPSS 0.3%CVE-2026-106109MEDIUMQuasar Framework: App Vite build cleanup can recursively remove unsafe configured output directoriesEPSS 0.1%
Referencias
https://github.com/quasarframework/quasar/commit/b719460aa78e88714b8a1b7ca68267234d217575https://github.com/quasarframework/quasar/releases/tag/@quasar/app-vite-v3.3.0https://github.com/quasarframework/quasar/releases/tag/@quasar/cli-v5.0.4https://github.com/quasarframework/quasar/security/advisories/GHSA-fh39-c73x-5pjv