Path Traversal and Arbitrary File Write in Quasar Icon Genie
The Quasar Icon Genie CLI tool is vulnerable to path traversal via malicious JSON configuration profiles, allowing attackers to overwrite arbitrary files on the local filesystem.
CVE search metadata
CVE search record: CVE-2026-106103. Severity: high. CVSS: 7.1. KEV: no. Brief: Path Traversal and Arbitrary File Write in Quasar Icon Genie. Brief link: https://feed.craftedsignal.io/briefs/2026-10-quasar-icongenie-traversal/
The Quasar Framework's Icon Genie CLI tool (specifically @quasar/icongenie) is vulnerable to a path traversal vulnerability (CVE-2026-106103) that allows arbitrary file writes on the host system. The vulnerability exists within the profile processing logic, where the folder and name attributes for icon assets are loaded from a user-supplied JSON file without adequate validation. The