Vulnerability DatabaseCVE-2026-106108

CVE-2026-106108: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-106108 is a path traversal vulnerability in the Quasar Framework's @quasar/app-vite npm package that allows SSG build output paths to escape the configured distribution directory. During a Static Site Generation (SSG) build, page definitions returned by getSsgPages() can supply custom dir and filename values that the builder joined to build.distDir without verifying the final destination remained within the distribution directory. The vulnerability affects @quasar/app-vite versions >= 3.1.0 and <= 3.2.0; version 3.3.0 contains the fix. It was originally published on July 29, 2026, and added to the GitHub Advisory Database on October 7, 2026, with a CVSS v4.0 base score of 5.7 (Medium) (GitHub Advisory, Quasar Security Advisory).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal): the SSG builder's getSsgPageFilename() function used Node.js path.join() to concatenate user-supplied dir and filename values from SsgPage definitions directly onto build.distDir without validating that the resolved path remained inside the output directory. An attacker who can influence SSG page definitions can supply path segments containing ../ sequences to traverse outside build.distDir, or leverage existing symlinks beneath the distribution directory to redirect file writes to arbitrary filesystem locations. The attack vector is local, requires high complexity and specific preconditions (the application must derive SSG page definitions from untrusted or external content, or the build configuration must be compromised), and requires active user interaction (triggering a quasar build -m ssg run). The fix introduced a new getContainedFilePath() utility that resolves paths against the real build.distDir, rejects absolute paths and parent-traversing segments, and verifies symlink-resolved ancestors remain within the output tree (GitHub Advisory, Fix Commit).

Impact

Successful exploitation allows an attacker to create new HTML files and directories outside the intended build.distDir with the permissions of the build user account. Existing files are protected by the SSG renderer's no-overwrite behavior, so overwriting sensitive files is not possible, but new files can be planted in arbitrary locations accessible to the build user. In CI/CD or automated build environments where the build user has elevated permissions, this could facilitate supply chain attacks, web shell placement, or configuration file injection that leads to further compromise (GitHub Advisory, Quasar Security Advisory).

Exploitability

No public proof-of-concept exploit code, in-the-wild exploitation, or threat actor attribution has been reported for this vulnerability. The CVE status is listed as Reserved, and no EPSS score or CISA KEV catalog entry is currently available. Exploitation is constrained by the requirement that an attacker must be able to influence the application's SSG page definitions — either through untrusted external content feeding into getSsgPages() or through a compromised build configuration — making opportunistic exploitation unlikely (GitHub Advisory, Feedly).

Exploitation steps

  1. Identify a target: Locate a Quasar application using @quasar/app-vite versions 3.1.0–3.2.0 that derives SSG page definitions from an external or attacker-influenced data source (e.g., a CMS API, database, or user-controlled configuration file).
  2. Craft a malicious page definition: Inject a SsgPage object with a dir or filename value containing path traversal sequences, such as dir: '../../etc' or filename: '../../../tmp/malicious.html', into the data source consumed by getSsgPages().
  3. Trigger the SSG build: Cause the application's build pipeline to execute quasar build -m ssg, either by committing to a repository with CI/CD integration, triggering a scheduled build, or through social engineering.
  4. File written outside distDir: The vulnerable getSsgPageFilename() function joins the traversal path to build.distDir without validation, causing the SSG renderer to write a new HTML file at the attacker-controlled path with the permissions of the build user.
  5. Leverage symlinks (alternative): If a symlink exists within build.distDir pointing outside the output tree, supply a dir or filename that resolves through that symlink to redirect the generated file to an arbitrary location (GitHub Advisory, Fix Commit).

Indicators of compromise

  • File System: Unexpected HTML files or directories created outside the configured build.distDir during or after an SSG build; new files in sensitive directories (e.g., /tmp, web server document roots, or application config directories) owned by the build user and timestamped to the build execution time.
  • Logs: Build logs from quasar build -m ssg showing page output paths containing ../ sequences or absolute paths; absence of expected error messages in builds using @quasar/app-vite < 3.3.0 when traversal paths are present.
  • Process: Unexpected file creation events (e.g., via inotifywait or auditd) by the Node.js build process outside the expected output directory during SSG build execution.
  • Configuration/Source: SSG page definition sources (CMS, API responses, config files) containing dir or filename values with ../ sequences, absolute paths, or references to symlinks within the distribution directory (GitHub Advisory).

Mitigation and workarounds

Upgrade @quasar/app-vite to version 3.3.0 or later, which introduces the getContainedFilePath() utility to validate all SSG page output paths against the real build.distDir, rejecting absolute paths, parent-traversing segments, and symlink escapes (Quasar Security Advisory, Fix Commit). As an interim workaround for teams unable to upgrade immediately, audit and sanitize all external data sources feeding into getSsgPages() to ensure dir and filename values are strictly relative paths without ../ sequences or absolute path components. Additionally, run SSG builds under a least-privilege user account to limit the impact of any unauthorized file writes.

Community reactions

The vulnerability was reported by community contributor hawkeye64 and patched by Quasar maintainer rstoenescu, who published the security advisory on July 29, 2026. No significant broader media coverage, researcher commentary, or notable social media discussion has been identified beyond the GitHub advisory and associated commit (Quasar Security Advisory).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-106557HIGH7.7
  • JavaScript logoJavaScript
  • @backstage/plugin-techdocs-node
NoYesOct 07, 2026
CVE-2026-106108MEDIUM5.6
  • JavaScript logoJavaScript
  • @quasar/app-vite
NoYesOct 07, 2026
CVE-2026-106563MEDIUM5.3
  • JavaScript logoJavaScript
  • @backstage/plugin-kubernetes-backend
NoYesOct 07, 2026
CVE-2026-106561MEDIUM5
  • JavaScript logoJavaScript
  • @backstage/plugin-kubernetes-backend
NoYesOct 07, 2026
CVE-2026-106562MEDIUM4.3
  • JavaScript logoJavaScript
  • @backstage/plugin-search-backend
NoYesOct 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management