PT-2026-106826 · Unknown · Quasar Framework
CVE-2026-106109
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v4.0
4.1
Medium
| Vector | AV:L/AC:H/AT:P/PR:H/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Quasar Framework versions 1.0.0 through 3.2.9
Description
The @quasar/app-vite component recursively removes the resolved
build.distDir before the build process begins. It fails to reject the project root, user home directory, filesystem roots, or symlink-resolved external directories. An unsafe configuration can lead to the deletion of data writable by the build user. Exploitation requires a developer to use a mistaken configuration or compromised automation to influence the build configuration, as attacker-controlled input does not reach build.distDir by default.Recommendations
Update to version 3.3.0.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Quasar Framework