GHSA-fh39-c73x-5pjv: Npm/@quasar/app-vite vulnerability
The @quasar/ssl-certificate development utility caches a combined PEM containing a generated private key and certificate without explicitly restricting its filesystem permissions. On systems with a typical process umask, the PEM can be readable by other local users. A local attacker with filesystem access could copy and reuse the private key to impersonate a development TLS endpoint in an environment that trusts the certificate.
The generated certificate was also unnecessarily CA-capable and included broad key usages beyond its localhost HTTPS purpose. Its IPv6 loopback entry was encoded as a DNS name rather than an IP subject alternative name.
The remediation writes and repairs the cached PEM with owner-only permissions on supported platforms, generates a non-CA server-auth leaf certificate with constrained key usage, corrects the IPv6 loopback SAN, and bases cache expiry on content modification time so permission metadata changes cannot extend the certificate lifetime. This issue does not expose the key remotely by itself; exploitation requires another local user to be able to read the cached PEM file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@quasar/app-viteto a version that resolves this vulnerability.Fixed in 3.3.0 - Upgrade
Upgrade
npm/@quasar/clito a version that resolves this vulnerability.Fixed in 5.0.4 - Upgrade
Upgrade
npm/@quasar/ssl-certificateto a version that resolves this vulnerability.Fixed in 2.1.0 - Configuration
Write and repair the cached PEM with owner-only filesystem permissions on supported platforms.
@quasar/ssl-certificate cached PEM filesystem permissions = owner-only - Configuration
Generate a non-CA server-auth leaf certificate with constrained key usage for localhost HTTPS.
@quasar/ssl-certificate generated certificate CA capability and key usage = non-CA server-auth leaf certificate with constrained key usage - Configuration
Encode the IPv6 loopback entry as an IP subject alternative name rather than a DNS name.
@quasar/ssl-certificate generated certificate IPv6 loopback subject alternative name = IP subject alternative name - Configuration
Base cache expiry on the cached PEM's content modification time so permission metadata changes cannot extend the certificate lifetime.
@quasar/ssl-certificate cache cache expiry basis = content modification time
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Systems where another local user can read the cached PEM file are exposed. The issue does not disclose the private key remotely by itself.
What does an attacker need to exploit it?
An attacker needs local filesystem access and permission to copy the cached combined PEM containing the generated private key. They could then reuse the key to impersonate a development TLS endpoint where the generated certificate is trusted.
Are the certificate's capabilities part of the risk?
Yes. The generated certificate was CA-capable and had broader key usages than needed for localhost HTTPS, increasing the consequences of private-key exposure.
What changes does the remediation make?
The remediation writes and repairs the cached PEM with owner-only permissions on supported platforms. It also generates a non-CA server-auth leaf certificate with constrained key usage, fixes the IPv6 loopback SAN, and uses content modification time for cache expiry so permission changes do not extend certificate lifetime.