CVE-2026-106109
Received Received - Intake

Path Traversal in Quasar Framework

Vulnerability report for CVE-2026-106109, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Quasar Framework is a framework for building high-performance Vue.js user interfaces. From 1.0.0 until 3.3.0, @quasar/app-vite recursively removed the resolved build.distDir before building without rejecting the project root, user home directory, filesystem roots, or symlink-resolved external directories. An unsafe trusted configuration can delete data writable by the build user before compilation begins. No attacker-controlled input reaches build.distDir by default, so exploitation requires compromised or less-trusted automation to influence build configuration, or a developer to run a mistaken configuration. This issue is fixed in version 3.3.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
quasarframework quasar >= 2.7.0, < 2.23.3
@quasar app-vite >= 1.0.0, < 3.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Quasar Framework versions 1.0.0 to 3.3.0 have a vulnerability where the build system recursively deletes the build output directory without checking if it is the project root, user home directory, filesystem root, or an external directory. This can lead to accidental deletion of critical data if the build directory is misconfigured.

Detection Guidance

Detection requires checking Quasar Framework versions and build configurations. Verify if @quasar/app-vite versions are between 1.0.0 and 3.3.0. Inspect build.distDir settings in project files for unsafe paths. No direct commands are provided in the context.

Impact Analysis

This vulnerability can cause data loss if the build directory is set to a sensitive location like the project root or home directory. It requires either compromised automation influencing the build configuration or a developer making a mistake in configuration.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR or HIPAA if it leads to unauthorized data deletion or disruption of systems handling sensitive personal or health information. The issue involves recursive directory removal during builds, which may compromise data integrity or availability if exploited in environments processing regulated data.

Mitigation Strategies

Upgrade @quasar/app-vite to version 3.3.0 or later. Review build configurations to ensure build.distDir does not point to critical directories like project root or home. Remove write permissions for build users in sensitive areas.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106109. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart