Impact
Quasar Framework’s icongenie tool accepts folder and name values from a user‑supplied profile without constraining the resolved destination, allowing parent‑directory traversal. The flaw lets a developer running icongenie generate --profile write or overwrite any file that the user can write, including shell startup files, build scripts, or other executable configuration. This constitutes an arbitrary file write that can enable remote code execution or compromise the build process, and is categorized as CWE‑22 and CWE‑73.
Affected Systems
Applications built with Quasar Framework that use icongenie before version 6.1.1 are impacted. The vulnerability affects the @quasar/icongenie package and the Quasar Framework components that invoke it. All releases of the icongenie tool dated before the 6.1.1 tag are vulnerable, regardless of the overall Quasar Framework version.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity. The EPSS score is not available, and the issue is not currently listed in CISA’s KEV catalog. The likely attack vector is a local developer who executes icongenie generate --profile with a crafted profile; the attacker must have write access to a path within the user’s environment. Once exploited, the attacker can overwrite critical files, potentially leading to code execution or system compromise.
OpenCVE Enrichment