
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-106108 is a path traversal vulnerability in the Quasar Framework's @quasar/app-vite npm package that allows SSG build output paths to escape the configured distribution directory. During a Static Site Generation (SSG) build, page definitions returned by getSsgPages() can supply custom dir and filename values that the builder joined to build.distDir without verifying the final destination remained within the distribution directory. The vulnerability affects @quasar/app-vite versions >= 3.1.0 and <= 3.2.0; version 3.3.0 contains the fix. It was originally published on July 29, 2026, and added to the GitHub Advisory Database on October 7, 2026, with a CVSS v4.0 base score of 5.7 (Medium) (GitHub Advisory, Quasar Security Advisory).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal): the SSG builder's getSsgPageFilename() function used Node.js path.join() to concatenate user-supplied dir and filename values from SsgPage definitions directly onto build.distDir without validating that the resolved path remained inside the output directory. An attacker who can influence SSG page definitions can supply path segments containing ../ sequences to traverse outside build.distDir, or leverage existing symlinks beneath the distribution directory to redirect file writes to arbitrary filesystem locations. The attack vector is local, requires high complexity and specific preconditions (the application must derive SSG page definitions from untrusted or external content, or the build configuration must be compromised), and requires active user interaction (triggering a quasar build -m ssg run). The fix introduced a new getContainedFilePath() utility that resolves paths against the real build.distDir, rejects absolute paths and parent-traversing segments, and verifies symlink-resolved ancestors remain within the output tree (GitHub Advisory, Fix Commit).
Successful exploitation allows an attacker to create new HTML files and directories outside the intended build.distDir with the permissions of the build user account. Existing files are protected by the SSG renderer's no-overwrite behavior, so overwriting sensitive files is not possible, but new files can be planted in arbitrary locations accessible to the build user. In CI/CD or automated build environments where the build user has elevated permissions, this could facilitate supply chain attacks, web shell placement, or configuration file injection that leads to further compromise (GitHub Advisory, Quasar Security Advisory).
No public proof-of-concept exploit code, in-the-wild exploitation, or threat actor attribution has been reported for this vulnerability. The CVE status is listed as Reserved, and no EPSS score or CISA KEV catalog entry is currently available. Exploitation is constrained by the requirement that an attacker must be able to influence the application's SSG page definitions — either through untrusted external content feeding into getSsgPages() or through a compromised build configuration — making opportunistic exploitation unlikely (GitHub Advisory, Feedly).
@quasar/app-vite versions 3.1.0–3.2.0 that derives SSG page definitions from an external or attacker-influenced data source (e.g., a CMS API, database, or user-controlled configuration file).SsgPage object with a dir or filename value containing path traversal sequences, such as dir: '../../etc' or filename: '../../../tmp/malicious.html', into the data source consumed by getSsgPages().quasar build -m ssg, either by committing to a repository with CI/CD integration, triggering a scheduled build, or through social engineering.getSsgPageFilename() function joins the traversal path to build.distDir without validation, causing the SSG renderer to write a new HTML file at the attacker-controlled path with the permissions of the build user.build.distDir pointing outside the output tree, supply a dir or filename that resolves through that symlink to redirect the generated file to an arbitrary location (GitHub Advisory, Fix Commit).build.distDir during or after an SSG build; new files in sensitive directories (e.g., /tmp, web server document roots, or application config directories) owned by the build user and timestamped to the build execution time.quasar build -m ssg showing page output paths containing ../ sequences or absolute paths; absence of expected error messages in builds using @quasar/app-vite < 3.3.0 when traversal paths are present.inotifywait or auditd) by the Node.js build process outside the expected output directory during SSG build execution.dir or filename values with ../ sequences, absolute paths, or references to symlinks within the distribution directory (GitHub Advisory).Upgrade @quasar/app-vite to version 3.3.0 or later, which introduces the getContainedFilePath() utility to validate all SSG page output paths against the real build.distDir, rejecting absolute paths, parent-traversing segments, and symlink escapes (Quasar Security Advisory, Fix Commit). As an interim workaround for teams unable to upgrade immediately, audit and sanitize all external data sources feeding into getSsgPages() to ensure dir and filename values are strictly relative paths without ../ sequences or absolute path components. Additionally, run SSG builds under a least-privilege user account to limit the impact of any unauthorized file writes.
The vulnerability was reported by community contributor hawkeye64 and patched by Quasar maintainer rstoenescu, who published the security advisory on July 29, 2026. No significant broader media coverage, researcher commentary, or notable social media discussion has been identified beyond the GitHub advisory and associated commit (Quasar Security Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."