GHSA-fh39-c73x-5pjv: Npm/@quasar/app-vite vulnerability

Published Oct 7, 2026
·
Updated

The @quasar/ssl-certificate development utility caches a combined PEM containing a generated private key and certificate without explicitly restricting its filesystem permissions. On systems with a typical process umask, the PEM can be readable by other local users. A local attacker with filesystem access could copy and reuse the private key to impersonate a development TLS endpoint in an environment that trusts the certificate.

The generated certificate was also unnecessarily CA-capable and included broad key usages beyond its localhost HTTPS purpose. Its IPv6 loopback entry was encoded as a DNS name rather than an IP subject alternative name.

The remediation writes and repairs the cached PEM with owner-only permissions on supported platforms, generates a non-CA server-auth leaf certificate with constrained key usage, corrects the IPv6 loopback SAN, and bases cache expiry on content modification time so permission metadata changes cannot extend the certificate lifetime. This issue does not expose the key remotely by itself; exploitation requires another local user to be able to read the cached PEM file.

Affected Software

3 affected componentsFixes available
npm/@quasar/app-vite<=3.2.0
3.3.0
npm/@quasar/cli<=5.0.3
5.0.4
npm/@quasar/ssl-certificate<=2.0.0
2.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@quasar/app-vite to a version that resolves this vulnerability.

    Fixed in 3.3.0
  2. Upgrade

    Upgrade npm/@quasar/cli to a version that resolves this vulnerability.

    Fixed in 5.0.4
  3. Upgrade

    Upgrade npm/@quasar/ssl-certificate to a version that resolves this vulnerability.

    Fixed in 2.1.0
  4. Configuration

    Write and repair the cached PEM with owner-only filesystem permissions on supported platforms.

    @quasar/ssl-certificate cached PEM filesystem permissions = owner-only
  5. Configuration

    Generate a non-CA server-auth leaf certificate with constrained key usage for localhost HTTPS.

    @quasar/ssl-certificate generated certificate CA capability and key usage = non-CA server-auth leaf certificate with constrained key usage
  6. Configuration

    Encode the IPv6 loopback entry as an IP subject alternative name rather than a DNS name.

    @quasar/ssl-certificate generated certificate IPv6 loopback subject alternative name = IP subject alternative name
  7. Configuration

    Base cache expiry on the cached PEM's content modification time so permission metadata changes cannot extend the certificate lifetime.

    @quasar/ssl-certificate cache cache expiry basis = content modification time

Event History

Oct 7, 2026
Advisory Published
via GitHub·04:16 PM
Data Sourced
via GitHub·04:16 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Systems where another local user can read the cached PEM file are exposed. The issue does not disclose the private key remotely by itself.

2

What does an attacker need to exploit it?

An attacker needs local filesystem access and permission to copy the cached combined PEM containing the generated private key. They could then reuse the key to impersonate a development TLS endpoint where the generated certificate is trusted.

3

Are the certificate's capabilities part of the risk?

Yes. The generated certificate was CA-capable and had broader key usages than needed for localhost HTTPS, increasing the consequences of private-key exposure.

4

What changes does the remediation make?

The remediation writes and repairs the cached PEM with owner-only permissions on supported platforms. It also generates a non-CA server-auth leaf certificate with constrained key usage, fixes the IPv6 loopback SAN, and uses content modification time for cache expiry so permission changes do not extend certificate lifetime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203