GHSA-5m6h-8g35-p3m7

Suggest an improvement
Source
https://github.com/advisories/GHSA-5m6h-8g35-p3m7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-5m6h-8g35-p3m7/GHSA-5m6h-8g35-p3m7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5m6h-8g35-p3m7
Aliases
Published
2026-10-07T16:16:03Z
Modified
2026-10-07T16:30:05Z
Severity
  • 8.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Quasar Framework: App Vite SSR and SSG nonce attributes are not safely constrained
Details

Several @quasar/app-vite SSR and SSG renderer paths interpolate ssrContext.nonce directly into quoted HTML attributes. An application that derives or overrides the nonce using untrusted data can allow a quote to terminate the nonce attribute and inject additional attributes or markup into generated HTML.

Cryptographically generated base64 or base64url nonces are not directly affected because they do not contain HTML attribute delimiters. Exploitation requires an application to place attacker-controlled or otherwise unsafe data in ssrContext.nonce.

The remediation centralizes nonce handling across development SSR/SSG, production SSR, production SSG, critical CSS, store-state scripts, and Vue Devtools. It validates the value as a non-empty base64/base64url CSP nonce and HTML-encodes the attribute value before rendering.

Database specific
{
    "cwe_ids": [
        "CWE-116",
        "CWE-79"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T16:16:03Z",
    "nvd_published_at": "2026-10-06T18:16:52Z",
    "severity": "HIGH"
}
References

Affected packages

npm / @quasar/app-vite

Package

Name
@quasar/app-vite
View open source insights on deps.dev
Purl
pkg:npm/%40quasar/app-vite

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.3.0

Database specific

last_known_affected_version_range
"<= 3.2.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-5m6h-8g35-p3m7/GHSA-5m6h-8g35-p3m7.json"