CVE-2026-106103: Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Genie profile
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values from a user-supplied profile without constraining the resolved destination to the Quasar project directory. icongenie/lib/utils/get-assets-files.js joined those values with appDir, while icongenie/lib/utils/validate-profile-object.js required only non-empty strings, allowing parent-directory traversal. A developer who runs a crafted profile can cause generated image content to be written or overwritten at any path writable by that user, potentially modifying shell startup files, build scripts, or other executable configuration. This issue is fixed in version 6.1.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@quasar/icongenieto a version that resolves this vulnerability.Fixed in 6.1.1
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Developers using @quasar/icongenie versions earlier than 6.1.1 are exposed when they run the generate command with a crafted profile. The vulnerable behavior occurs on the developer's machine under the permissions of the user running the command.
What does an attacker need to exploit it?
An attacker needs to provide a profile containing crafted folder or name values and induce a developer to run icongenie generate --profile with that profile. The target path must be writable by the developer running the command.
What can be done before updating?
Do not run Icon Genie profiles from untrusted sources. Review profile folder and name values and reject values that use parent-directory traversal or would resolve outside the intended Quasar project directory.
What is the potential impact of a successful exploit?
Generated image content can be written to or overwrite any path writable by the user running Icon Genie. This could modify shell startup files, build scripts, or other executable configuration files.