Description
[email protected], the latest published version at the time of testing, appears to be vulnerable to prototype pollution through the public extend() utility exported from the package root.
Recommendation
Update the quasar package to the latest compatible version. Followings are version details:
- Affected version(s): <= 2.21.4
- Patched version(s): 2.22.0
References
Could your website be exposed too?
SmartScanner can check your website for Quasar: Prototype pollution in the extend() utility and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Mermaid configuration APIs allow prototype pollution - CVE-2026-71438
- CASL Ability is Vulnerable to Prototype Pollution - CVE-2026-1774
- Mermaid Architecture diagrams are vulnerable to prototype pollution - CVE-2026-71437
- set-in Affected by Prototype Pollution - CVE-2026-26021
You might also like:
See something that needs correcting? Let us knowUpdated August 13, 2026


