GHSA-89vp-x45c-52cq: Low severity npm/quasar vulnerability

Published Oct 7, 2026
·
Updated

Summary

A DOM Clobbering vulnerability exists in Quasar's openURL() utility when handling the iOS SafariViewController bridge.

The vulnerable implementation only checks whether window.SafariViewController exists before invoking it as a native bridge object. An attacker who can inject HTML content containing a named element such as <a id="SafariViewController"> can cause the browser to expose that element as window.SafariViewController.

When openURL() is later called in an iOS environment, Quasar incorrectly treats the DOM element as the native bridge object and attempts to invoke bridge methods that do not exist, resulting in:

TypeError: window.SafariViewController.isAvailable is not a function

This can cause client-side denial of service and break navigation-related workflows in Quasar applications.

Details

Quasar provides the openURL() utility to open external URLs. On iOS platforms, this utility supports integration with the native SafariViewController bridge.

The vulnerable code is located in:

ui/src/utils/open-url/open-url.js

The affected logic is:

javascript if (Platform.is.ios && window.SafariViewController !== void 0) { window.SafariViewController.isAvailable(available => { if (available) { window.SafariViewController.show({ url }, noop, reject) } }) }

The issue is that Quasar only verifies that window.SafariViewController is not undefined. It does not verify whether the value is the expected native bridge object or whether required methods such as isAvailable() and show() are valid functions.

Modern browsers expose elements with specific id or name attributes as properties of the global window object. Therefore, attacker-controlled HTML such as:

html <a id="SafariViewController"></a>

can cause:

javascript window.SafariViewController

to resolve to an HTMLAnchorElement instead of the expected native bridge object.

When Quasar later executes:

javascript window.SafariViewController.isAvailable(...)

the DOM element is incorrectly treated as the bridge object, causing:

TypeError: window.SafariViewController.isAvailable is not a function

The root cause is insufficient validation of browser-controlled global properties before using them as trusted native bridge objects.

The vulnerability was verified through the Quasar QEditor rendering path. When attacker-controlled HTML content is rendered into the DOM and creates the SafariViewController named element, subsequent calls to openURL() fail.

Additional component-level affected paths were identified in QSelect and QChatMessage when applications enable HTML rendering features and provide attacker-controlled content. These paths require specific application configurations and were not used as the primary end-to-end reproduction.

PoC

Steps to reproduce

1. Render attacker-controlled HTML content through a Quasar HTML rendering component such as QEditor. 2. Insert the following payload: html <a id="SafariViewController" href="#bridge"> SafariViewController </a>

3. Verify that the browser exposes the element as a global property:

javascript window.SafariViewController

The value resolves to the injected DOM element instead of the expected native bridge object.

4. Trigger a normal workflow that invokes:

javascript openURL('https://example.com')

5. Observe the browser console output:

TypeError: window.SafariViewController.isAvailable is not a function

The URL opening workflow fails because Quasar attempts to invoke native bridge methods on the DOM element.

The same underlying issue can also affect other HTML rendering paths such as QSelect and QChatMessage when attacker-controlled HTML is rendered and the application later calls openURL().

Impact

This vulnerability is a client-side DOM Clobbering and type confusion issue affecting Quasar applications that use the iOS SafariViewController integration. An attacker who can control HTML content rendered into the application DOM may cause Quasar's openURL() functionality to fail by replacing the expected native bridge object with a DOM element through browser named property resolution.

Potentially affected workflows include external URL navigation, OAuth/login redirects, help or documentation links, payment flows, third-party service redirects, and other application actions that rely on URL opening functionality.

The confirmed impact is client-side denial of service and navigation or workflow disruption. When the vulnerable condition is triggered, Quasar throws an exception while attempting to invoke methods on the clobbered SafariViewController object, preventing the expected URL opening behavior.

Affected Software

1 affected componentFixes available
npm/quasar<=2.32.1
2.32.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/quasar to a version that resolves this vulnerability.

    Fixed in 2.32.2

Event History

Oct 7, 2026
Advisory Published
via GitHub·08:23 PM
Data Sourced
via GitHub·08:23 PM
DescriptionSeverityWeaknessAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203