๐Ÿ” CVE Alert

CVE-2026-106103

HIGH 7.1

Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Genie profile

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values from a user-supplied profile without constraining the resolved destination to the Quasar project directory. icongenie/lib/utils/get-assets-files.js joined those values with appDir, while icongenie/lib/utils/validate-profile-object.js required only non-empty strings, allowing parent-directory traversal. A developer who runs a crafted profile can cause generated image content to be written or overwritten at any path writable by that user, potentially modifying shell startup files, build scripts, or other executable configuration. This issue is fixed in version 6.1.1.

CWE CWE-22 CWE-73
Vendor quasarframework
Product quasar
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for quasarframework quasar

Be the first to know when new high vulnerabilities affecting quasarframework quasar are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High

Affected Versions

quasarframework / quasar
< 2.22.0
@quasar / icongenie
< 6.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/quasarframework/quasar/security/advisories/GHSA-wmpw-j6qv-mw88 github.com: https://github.com/quasarframework/quasar/commit/87c89a80ec84f1eb7dbe258e5367161b0598ceb3 github.com: https://github.com/quasarframework/quasar/releases/tag/@quasar/icongenie-v6.1.1