Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fh39-c73x-5pjv | Quasar Framework: Development TLS private keys are cached with overly permissive filesystem permissions |
Fri, 09 Oct 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quasarframework
Quasarframework app-vite Quasarframework cli Quasarframework quasar Quasarframework ssl-certificate |
|
| Vendors & Products |
Quasarframework
Quasarframework app-vite Quasarframework cli Quasarframework quasar Quasarframework ssl-certificate |
Tue, 06 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/ssl-certificate 2.1.0, @quasar/cli 5.0.4, and @quasar/app-vite 3.3.0, the @quasar/ssl-certificate utility cached a combined private key and certificate PEM without explicitly applying owner-only filesystem permissions. Another local user able to read the cache can copy the key and impersonate a development TLS endpoint in an environment that trusts the certificate. The generated certificate was also CA-capable, carried unnecessarily broad key usages, and encoded the IPv6 loopback address as a DNS subject alternative name. This issue is fixed in @quasar/ssl-certificate 2.1.0, @quasar/cli 5.0.4, and @quasar/app-vite 3.3.0. | |
| Title | Quasar Framework: Development TLS private keys are cached with overly permissive filesystem permissions | |
| Weaknesses | CWE-732 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T17:53:57.230Z
Reserved: 2026-10-06T15:33:55.333Z
Link: CVE-2026-106105
No data.
Status : Awaiting Analysis
Published: 2026-10-06T18:16:51.833
Modified: 2026-10-06T20:03:40.690
Link: CVE-2026-106105
No data.
OpenCVE Enrichment
Updated: 2026-10-09T08:43:47Z
-
CWE-732
Incorrect Permission Assignment for Critical Resource
Github GHSA