CVE-2026-106103: Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Genie profile

Published Oct 6, 2026
·
Updated

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values from a user-supplied profile without constraining the resolved destination to the Quasar project directory. icongenie/lib/utils/get-assets-files.js joined those values with appDir, while icongenie/lib/utils/validate-profile-object.js required only non-empty strings, allowing parent-directory traversal. A developer who runs a crafted profile can cause generated image content to be written or overwritten at any path writable by that user, potentially modifying shell startup files, build scripts, or other executable configuration. This issue is fixed in version 6.1.1.

Affected Software

1 affected component
npm/@quasar/icongenie<6.1.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade @quasar/icongenie to a version that resolves this vulnerability.

    Fixed in 6.1.1

Event History

Oct 6, 2026
CVE Published
via MITRE·05:11 PM
Data Sourced
via MITRE·05:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Developers using @quasar/icongenie versions earlier than 6.1.1 are exposed when they run the generate command with a crafted profile. The vulnerable behavior occurs on the developer's machine under the permissions of the user running the command.

2

What does an attacker need to exploit it?

An attacker needs to provide a profile containing crafted folder or name values and induce a developer to run icongenie generate --profile with that profile. The target path must be writable by the developer running the command.

3

What can be done before updating?

Do not run Icon Genie profiles from untrusted sources. Review profile folder and name values and reject values that use parent-directory traversal or would resolve outside the intended Quasar project directory.

4

What is the potential impact of a successful exploit?

Generated image content can be written to or overwrite any path writable by the user running Icon Genie. This could modify shell startup files, build scripts, or other executable configuration files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203