Advisories for Npm/@Quasar/Ssl-Certificate package

2026

Quasar Framework: Development TLS private keys are cached with overly permissive filesystem permissions

The @quasar/ssl-certificate development utility caches a combined PEM containing a generated private key and certificate without explicitly restricting its filesystem permissions. On systems with a typical process umask, the PEM can be readable by other local users. A local attacker with filesystem access could copy and reuse the private key to impersonate a development TLS endpoint in an environment that trusts the certificate. The generated certificate was also unnecessarily CA-capable …