{"id":"CVE-2026-73647","aliases":["GHSA-3r53-75j5-3g7j"],"url":"https://o3.security/vulnerability/CVE-2026-73647","summary":"Quasar Framework: Prototype pollution in Quasar extend() utility","details":"### Summary\n\n`quasar@2.20.1`, the latest published version at the time of testing, appears to be vulnerable to prototype pollution through the public `extend()` utility exported from the package root.\n\nWhen `extend(true, target, source)` is used for a deep merge, attacker-controlled object keys are recursively copied into the target object without blocking prototype-pollution primitives such as `__proto__`, `constructor`, or `prototype`.\n\nThis can allow attacker-controlled properties to be written to `Object.prototype`.\n\n### Details\n\nAffected source:\n\n```text\nsrc/utils/extend/extend.js\n```\n\nDistributed files include:\n\n```text\ndist/quasar.server.prod.js\ndist/quasar.server.prod.cjs\ndist/quasar.client.js\n```\n\nThe package root publicly exports `extend`. During deep merge, source object keys are recursively assigned into the target object. If the source object contains an own `__proto__` property, the merge can descend into the prototype object and assign attacker-controlled properties onto `Object.prototype`.\n\n### PoC\n\n```bash\nrm -rf /tmp/quasar-extend-pp-poc\nmkdir /tmp/quasar-extend-pp-poc\ncd /tmp/quasar-extend-pp-poc\n\nnpm init -y >/dev/null\nnpm install quasar@2.20.1 vue@3.5.31 >/dev/null\n\ncat > hack.mjs <<'JS'\nimport { extend } from 'quasar';\n\ndelete Object.prototype.polluted;\n\nextend(true, {}, {\n  ['__proto__']: {\n    polluted: 'yes'\n  }\n});\n\nconsole.log(({}).polluted);\n\ndelete Object.prototype.polluted;\nJS\n\nnode ./hack.mjs\n```\n\nObserved output:\n\n```text\nyes\n```\n\nExpected output:\n\n```text\nundefined\n```\n\n### Impact\n\nThis is a prototype pollution vulnerability.\n\nIf an application passes user-controlled or partially user-controlled objects into `extend(true, ...)`, an attacker may be able to pollute `Object.prototype` in the same JavaScript process.\n\nDepending on how the polluted property is later consumed, this may lead to logic bypass, unsafe default option injection, denial of service, or other application-specific security impact.\n\n### Suggested Fix\n\nReject or safely ignore dangerous keys before assignment, including:\n\n```text\n__proto__\nprototype\nconstructor\n```\n\nThe merge implementation should also avoid descending into prototype-related properties during recursive merge.","published":"2026-08-13T17:57:09.014Z","modified":"2026-09-11T03:30:52.328264004Z","cvss":{"score":5.6,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":{"score":0.0038,"percentile":0.31533,"asOf":"2026-09-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"quasar","fixedVersion":"2.22.0"}],"fix":{"url":"https://github.com/quasarframework/quasar/commit/d0a95d95ab3c29d13e1b8ba8c5e5025fd6ce35e7","label":"quasarframework/quasar@d0a95d9"},"references":[{"type":"WEB","url":"https://github.com/quasarframework/quasar/releases/tag/quasar-v2.22.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73647.json"},{"type":"ADVISORY","url":"https://github.com/quasarframework/quasar/security/advisories/GHSA-3r53-75j5-3g7j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73647"},{"type":"FIX","url":"https://github.com/quasarframework/quasar/commit/d0a95d95ab3c29d13e1b8ba8c5e5025fd6ce35e7"},{"type":"PACKAGE","url":"https://github.com/quasarframework/quasar"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-11T03:30:52.328264004Z"}}