Sceawere
Vulnerability Detail
CVE-2026-106101UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Quasar openURL Prototype Pollution Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.1
- Creation Date
- 8h ago
- Vendor
- quasarframework
- Product
- quasar
- Attack Type
- CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.32.2, the openURL() utility in ui/src/utils/open-url/open-url.js trusted window.SafariViewController whenever that global existed in an iOS environment. Attacker-controlled HTML rendered by components such as QEditor can create a named SafariViewController element, causing browser named-property resolution to replace the expected native bridge object. A later openURL() call then invokes isAvailable() on the element, throws a TypeError, and disrupts external navigation, login redirects, payment redirects, and other URL-opening workflows. QSelect and QChatMessage HTML-rendering configurations can expose the same trigger when they render attacker-controlled HTML. This issue is fixed in version 2.32.2.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.1",
"pubDate": "2026-10-06T17:17:24.110Z",
"pubdate": "2026-10-06T17:17:24.110Z",
"executiveSummary": "A vulnerability exists in the Quasar Framework's openURL() utility, which is susceptible to object property shadowing via browser named-property resolution.\nThe issue affects versions prior to 2.32.2 and is triggered when components like QEditor, QSelect, or QChatMessage render attacker-controlled HTML within an iOS environment.\nBy injecting a named element that mimics the window.SafariViewController object, an attacker can hijack the global namespace, causing the native bridge resolution to fail.\nThis leads to a Denial of Service (DoS) condition regarding external navigation, effectively breaking critical workflows such as authentication redirects, payment processing, and URL dispatching.\nThe vulnerability requires the rendering of untrusted content within the application but does not necessitate elevated privileges or authentication, representing a significant risk to application availability and core utility functionality.\nThe impact is primarily localized to the client-side execution environment on iOS, where the browser's property lookup mechanism prioritizes named HTML elements over the intended native bridge interface.",
"technicalDetails": "The root cause of this vulnerability lies in the insecure reliance on the existence of the window.SafariViewController global object within the ui/src/utils/open-url/open-url.js utility. In an iOS environment, Quasar checks for the existence of this global to determine if it should leverage a native Safari view controller for external URL navigation.\nThe vulnerability is exploited through browser-level named-property resolution. When an HTML document contains an element with a name attribute matching a global variable name, the browser may map that element directly onto the window object. An attacker who can influence the HTML rendered by the application—specifically through components that support HTML rendering like QEditor, QSelect, or QChatMessage—can inject an element with the name 'SafariViewController'.\nOnce the attacker-controlled element is injected, it shadows the legitimate native SafariViewController object. When a subsequent call to openURL() occurs, the utility checks if window.SafariViewController exists. The check returns true, as the injected element is now occupying that namespace. The utility then attempts to invoke the .isAvailable() method on this object. Since the injected HTML element does not possess this method, a TypeError is triggered in the JavaScript execution context.\nThe attack flow follows these steps: 1) The attacker identifies a component that renders unsanitized HTML (e.g., QEditor). 2) The attacker submits a payload containing an HTML element with 'name=SafariViewController'. 3) The browser's DOM parser or property resolution mechanism promotes this element to the global scope. 4) The application attempts to invoke openURL(), triggering the utility to interact with the attacker-controlled element instead of the native API. 5) A TypeError is thrown, halting the navigation logic.\nThis behavior results in a complete disruption of URL-opening workflows. Because this affects redirects integral to identity providers or payment gateways, it can lead to session lockouts or business logic failures. The vulnerability is present in all versions prior to 2.32.2. No authentication is required, as the vector is purely client-side exploitation of rendering logic.\nPost-exploitation, the application remains in a degraded state for the remainder of the session, as the window-level object modification persists. Mitigation is achieved by ensuring that the utility verifies the type and expected structure of the global object before attempting method invocation."
}