Directory Traversal Vulnerability in Quasar Framework's IconGenie Command
CVE-2026-106103
7.1HIGH
What is CVE-2026-106103?
The Quasar Framework's IconGenie command earlier than version 6.1.1 is susceptible to a directory traversal vulnerability. The improper validation of user-supplied folder and name values in the icongenie generate --profile command allows potential attackers to manipulate the file paths. This could lead to unauthorized file creation or overwriting in locations writable by the user, including sensitive configuration files or scripts. The issue has been addressed in version 6.1.1, which enforces stricter constraints on the destination paths to prevent such vulnerabilities.
Affected Version(s)
icongenie < 6.1.1
quasar < 2.22.0
