Advisories for Npm/@Quasar/Render-Ssr-Error package

2026

Quasar Framework: SSR/SSG dev error page discloses the full shell environment and its </script> escape is bypassable

The error page that Quasar CLI shows when an SSR or SSG render throws in development serializes every variable in process.env, every request header and every cookie into the HTTP response, and the dev server binds 0.0.0.0 by default. Any host that can reach the port therefore gets the developer's cloud keys, registry tokens and database URLs from a single unauthenticated GET. The same page embeds that data inside a …