A vulnerability was found in Quasar Framework Quasar up to 2.21.x. It has been rated as critical. This impacts the function
extend of the file ui/src/utils/extend/extend.js of the component Deep Merge. Performing a manipulation results in injection.
This vulnerability is cataloged as CVE-2026-73647. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.