Sceawere
Vulnerability Detail
CVE-2026-106103UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Icongenie Path Traversal Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 7h ago
- Vendor
- quasarframework
- Product
- quasar
- Attack Type
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values from a user-supplied profile without constraining the resolved destination to the Quasar project directory. icongenie/lib/utils/get-assets-files.js joined those values with appDir, while icongenie/lib/utils/validate-profile-object.js required only non-empty strings, allowing parent-directory traversal. A developer who runs a crafted profile can cause generated image content to be written or overwritten at any path writable by that user, potentially modifying shell startup files, build scripts, or other executable configuration. This issue is fixed in version 6.1.1.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T18:16:51.523Z",
"pubdate": "2026-10-06T18:16:51.523Z",
"executiveSummary": "A critical path traversal vulnerability exists in the @quasar/icongenie package, affecting versions prior to 6.1.1. The vulnerability originates from improper validation of user-supplied folder and name parameters within profile configurations used by the 'icongenie generate --profile' command.\nBy leveraging directory traversal sequences (e.g., '../'), an attacker can escape the intended Quasar project directory context. This flaw allows for the arbitrary writing or overwriting of files anywhere on the local filesystem that the user executing the tool has permissions to access.\nThe risk implication is severe, as successful exploitation enables an attacker to compromise the integrity of the development environment. By overwriting sensitive files such as shell startup scripts (e.g., .bashrc or .zshrc), build configuration files, or other executable binaries, an attacker can achieve code execution within the context of the user running the command.\nThis vulnerability does not require authentication or network access, as it relies on the execution of a malicious profile configuration by a developer. Remediation involves upgrading @quasar/icongenie to version 6.1.1 or later, where input sanitization logic prevents directory breakout.",
"technicalDetails": "The root cause of the vulnerability lies in the insufficient input validation within 'icongenie/lib/utils/validate-profile-object.js' and the insecure file path construction in 'icongenie/lib/utils/get-assets-files.js'. The validation logic only enforces a requirement for non-empty strings, failing to sanitize or restrict input characters that could facilitate directory traversal.\nWhen a user executes 'icongenie generate --profile', the application processes the user-provided profile object. The vulnerable 'get-assets-files.js' module takes the 'folder' and 'name' properties from this object and performs a path concatenation with the 'appDir' variable. Because the input is not normalized or validated against path traversal characters like '..', the resulting path is resolved relative to the filesystem root rather than the intended project directory.\nThe exploitation flow proceeds as follows: 1) An attacker creates a crafted Quasar profile object, specifying a 'folder' or 'name' attribute containing multiple directory traversal sequences (e.g., '../../../../home/user/.bashrc'). 2) The attacker induces a developer or automated system to run the 'icongenie generate --profile' command using this malicious profile. 3) The 'icongenie' tool processes the object and passes the unsanitized path strings to the underlying file system write operation. 4) The application resolves the manipulated path and writes image data to the attacker-specified target location.\nThis vulnerability facilitates arbitrary file overwrite, effectively allowing an attacker to inject malicious content into sensitive system or project files. If the target file is an executable or a configuration script that is parsed upon shell invocation, the attacker can achieve persistent code execution. Since the tool operates with the privileges of the user running the CLI command, the impact is strictly limited to the file system permissions granted to that user. No network exposure is required for this attack, as it is a client-side execution flaw, rendering it particularly dangerous for developers who might unknowingly import or use untrusted third-party profile configurations."
}