Directory Traversal Vulnerability in Quasar Framework's IconGenie Command
CVE-2026-106103

7.1HIGH

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106103?

The Quasar Framework's IconGenie command earlier than version 6.1.1 is susceptible to a directory traversal vulnerability. The improper validation of user-supplied folder and name values in the icongenie generate --profile command allows potential attackers to manipulate the file paths. This could lead to unauthorized file creation or overwriting in locations writable by the user, including sensitive configuration files or scripts. The issue has been addressed in version 6.1.1, which enforces stricter constraints on the destination paths to prevent such vulnerabilities.

Affected Version(s)

icongenie < 6.1.1

quasar < 2.22.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.