SCA: security update for quasar (GHSA-3r53-75j5-3g7j)

medium Tenable Self-Hosted Container Security Plugin ID 445364

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the
public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object
keys during extend(true, target, source) deep merges without rejecting an own __proto__ property. The
merge could descend into the prototype object and write attacker-controlled properties to Object.prototype
in the same JavaScript process. Applications that passed user-controlled or partially user-controlled
objects to extend() could experience logic bypass, unsafe default-option injection, denial of service, or
other application-specific impact when polluted properties were later consumed. This issue is fixed in
version 2.22.0. (CVE-2026-73647)

Solution

Update the quasar library and its related packages to version 2.22.0 or later.

See Also

https://github.com/advisories/GHSA-3r53-75j5-3g7j

Plugin Details

Severity: Medium

ID: 445364

Version: Revision 1.3

Type: Local

Family: SCA Checks

Published: 7/25/2026

Updated: 8/14/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.8

Percentile: 22.41

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.1

Temporal Score: 3.8

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2026-73647

CVSS v3

Risk Factor: Medium

Base Score: 5.6

Temporal Score: 4.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/24/2026

Vulnerability Publication Date: 7/24/2026

Reference Information

CVE: CVE-2026-73647