This is incorrect; the problem is that htmlspecialchars() doesn't know to escape {{ }}, and that that then allows user input to get interpreted as Vue template expressions.
If you have a sanitizer that cleans up ' and ", that'd only serve to limit the vulnerability to executing javascript without quotations in it. That's nowhere near a comfortable place to be - user data should not end up interpreted as Javascript, quotations or not.