CVE-2026-106103
Last modified
CVE-2026-106103 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values from a user-supplied profile without constraining the resolved destination to the Quasar project directory.
Description
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values from a user-supplied profile without constraining the resolved destination to the Quasar project directory. icongenie/lib/utils/get-assets-files.js joined those values with appDir, while icongenie/lib/utils/validate-profile-object.js required only non-empty strings, allowing parent-directory traversal. A developer who runs a crafted profile can cause generated image content to be written or overwritten at any path writable by that user, potentially modifying shell startup files, build scripts, or other executable configuration. This issue is fixed in version 6.1.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| quasarframework | quasar | < 2.22.0 |
| @quasar | icongenie | < 6.1.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-106103?
How severe is CVE-2026-106103?
How do I fix CVE-2026-106103?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10609A missing authorization flaw was found in the OpenShift Clus…6.8
- CVE-2026-1061A vulnerability was detected in xiweicheng TMS up to 2.28.0.…9.8
- CVE-2026-10610Local privilege escalation potentially allowed an attacker t…8.5
- CVE-2026-106100Payload is a free and open source headless content managemen…7.1
- CVE-2026-106101Quasar Framework is a framework for building high-performanc…3.1
- CVE-2026-106102Quasar Framework is a framework for building high-performanc…10
- CVE-2026-106104Quasar Framework is a framework for building high-performanc…8.7
- CVE-2026-106105Quasar Framework is a framework for building high-performanc…8.4
- CVE-2026-106106Quasar Framework is a framework for building high-performanc…7.1
- CVE-2026-106107Quasar Framework is a framework for building high-performanc…8.3
- CVE-2026-106109Quasar Framework is a framework for building high-performanc…4.1
- CVE-2026-10611An authentication bypass vulnerability exists in MISP when L…10
Are you affected by CVE-2026-106103?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
