npm package reportIs @quasar/app-vite safe ? 5 known vulnerabilities, worst severity HIGH.
// reach 32 direct dependencies
11 carry known advisories, worst CRITICAL
0 packages depend on it
an advisory here reaches each of them
// ai model usage Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.
epss chance of exploitation in 30 days
xyz score CyberXYZ composite out of 10
fig. 01 — GHSA-5m6h-8g35-p3m7, the advisory selected below
// 5 advisories GHSA-5m6h-8g35-p3m7 Several @quasar/app-vite SSR and SSG renderer paths interpolate ssrContext.nonce directly into quoted HTML attributes. An application that derives or overrides the nonce using untrusted data can allow a quote to terminate the nonce attribute and inject additional attributes or markup into generated HTML. HIGH GHSA-r5mf-4r5x-q78f The error page that Quasar CLI shows when an SSR or SSG render throws in development serializes every variable in process.env, every request header and every cookie into the HTTP response, and the dev server binds 0.0.0.0 by default. Any host that can reach the port therefore gets the developer's cloud keys, registry tokens and database URLs from a single unauthenticated GET. The same page embeds HIGH GHSA-fh39-c73x-5pjv The @quasar/ssl-certificate development utility caches a combined PEM containing a generated private key and certificate without explicitly restricting its filesystem permissions. On systems with a typical process umask, the PEM can be readable by other local users. A local attacker with filesystem access could copy and reuse the private key to impersonate a development TLS endpoint in an environm HIGH GHSA-q9mq-245r-4g93 @quasar/app-vite recursively removes build.distDir before producing build artifacts. The configured path was made absolute, but it was not checked before removal. A configuration mistake could therefore target the project root, user home directory, a filesystem root, or another directory outside the project. MODE GHSA-vhhq-m2gm-rwc9 During an SSG build, page definitions returned by getSsgPages() can provide custom dir and filename values. The builder joined those values to build.distDir and wrote the generated page without verifying that the final destination remained inside the distribution directory. MODE Several @quasar/app-vite SSR and SSG renderer paths interpolate ssrContext.nonce directly into quoted HTML attributes. An application that derives or overrides the nonce using untrusted data can allow a quote to terminate the nonce attribute and inject additional attributes or markup into generated HTML.
Cryptographically generated base64 or base64url nonces are not directly affected because they do not contain HTML attribute delimiters. Exploitation requires an application to place attacker-controlled or otherwise unsafe data in ssrContext.nonce.
The remediation centralizes nonce handling across development SSR/SSG, production SSR, production SSG, critical CSS, store-state scripts, and Vue Devtools. It validates the value as a non-empty base64/base64url CSP nonce and HTML-encodes the attribute value before rendering.
// cvss v4.0 vector CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Attack vector Network
Attack complexity High
Attack requirements Present
Privileges required None
User interaction None
Confidentiality (vulnerable system) Low
Integrity (vulnerable system) High
Availability (vulnerable system) None
Confidentiality (subsequent systems) None
Integrity (subsequent systems) None
Availability (subsequent systems) None Checked 2026-10-07 at 18:32 UTC. The most recent advisory here was published 2026-10-07. Updated continuously from NVD, GHSA, OSV and CNA feeds.
Think a verdict here is wrong? Tell us — we respond within 2 business days. Report an issue with this page