PT-2026-106826 · Unknown · Quasar Framework

CVE-2026-106109

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v4.0

4.1

Medium

VectorAV:L/AC:H/AT:P/PR:H/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Quasar Framework versions 1.0.0 through 3.2.9
Description The @quasar/app-vite component recursively removes the resolved build.distDir before the build process begins. It fails to reject the project root, user home directory, filesystem roots, or symlink-resolved external directories. An unsafe configuration can lead to the deletion of data writable by the build user. Exploitation requires a developer to use a mistaken configuration or compromised automation to influence the build configuration, as attacker-controlled input does not reach build.distDir by default.
Recommendations Update to version 3.3.0.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106109
GHSA-Q9MQ-245R-4G93

Affected Products

Quasar Framework