Vulnerability in Quasar Framework Affects Vue.js User Interface Builds
CVE-2026-106109

4.1MEDIUM

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106109?

The Quasar Framework, designed for building high-performance Vue.js user interfaces, has a vulnerability in the @quasar/app-vite package that affects versions from 1.0.0 up to 3.3.0. This issue arises due to the framework's unsafe configuration allowing the recursive removal of the build.distDir without adequate safeguards. As a result, a compromised automation environment or misconfigured build process could potentially lead to unintended data deletion in user directories, adversely affecting project integrity. It's crucial for developers to verify their build configurations and update to version 3.3.0, where this vulnerability has been addressed.

Affected Version(s)

app-vite >= 1.0.0, < 3.3.0

quasar >= 2.7.0, < 2.23.3

References

CVSS V4

Score:
4.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.