Description
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values from a user-supplied profile without constraining the resolved destination to the Quasar project directory. icongenie/lib/utils/get-assets-files.js joined those values with appDir, while icongenie/lib/utils/validate-profile-object.js required only non-empty strings, allowing parent-directory traversal. A developer who runs a crafted profile can cause generated image content to be written or overwritten at any path writable by that user, potentially modifying shell startup files, build scripts, or other executable configuration. This issue is fixed in version 6.1.1.
Published: 2026-10-06
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Quasar Framework’s icongenie tool accepts folder and name values from a user‑supplied profile without constraining the resolved destination, allowing parent‑directory traversal. The flaw lets a developer running icongenie generate --profile write or overwrite any file that the user can write, including shell startup files, build scripts, or other executable configuration. This constitutes an arbitrary file write that can enable remote code execution or compromise the build process, and is categorized as CWE‑22 and CWE‑73.

Affected Systems

Applications built with Quasar Framework that use icongenie before version 6.1.1 are impacted. The vulnerability affects the @quasar/icongenie package and the Quasar Framework components that invoke it. All releases of the icongenie tool dated before the 6.1.1 tag are vulnerable, regardless of the overall Quasar Framework version.

Risk and Exploitability

The CVSS score is 7.1, indicating a high severity. The EPSS score is not available, and the issue is not currently listed in CISA’s KEV catalog. The likely attack vector is a local developer who executes icongenie generate --profile with a crafted profile; the attacker must have write access to a path within the user’s environment. Once exploited, the attacker can overwrite critical files, potentially leading to code execution or system compromise.

Generated by OpenCVE AI on October 6, 2026 at 19:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade @quasar/icongenie to 6.1.1 or later and update the Quasar Framework to the corresponding release that includes this patch.
  • If an immediate upgrade is not feasible, validate profile inputs to reject any folder or name that resolves outside the Quasar project root, effectively eliminating parent‑directory traversal.
  • Restrict the execution of icongenie generate --profile to trusted developers or CI systems, ensuring that only users with secured permissions can invoke the command and write files.

Generated by OpenCVE AI on October 6, 2026 at 19:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values from a user-supplied profile without constraining the resolved destination to the Quasar project directory. icongenie/lib/utils/get-assets-files.js joined those values with appDir, while icongenie/lib/utils/validate-profile-object.js required only non-empty strings, allowing parent-directory traversal. A developer who runs a crafted profile can cause generated image content to be written or overwritten at any path writable by that user, potentially modifying shell startup files, build scripts, or other executable configuration. This issue is fixed in version 6.1.1.
Title Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Genie profile
Weaknesses CWE-22
CWE-73
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T19:42:52.902Z

Reserved: 2026-10-06T15:33:55.333Z

Link: CVE-2026-106103

cve-icon Vulnrichment

Updated: 2026-10-06T19:42:48.412Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T18:16:51.523

Modified: 2026-10-06T20:17:17.230

Link: CVE-2026-106103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T19:15:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-73

    External Control of File Name or Path