PatchSiren cyber security CVE debrief
CVE-2026-106108 quasarframework CVE debrief
CVE-2026-106108 debrief: The Quasar Framework's App Vite SSG page output paths can escape the configured distribution directory due to improper handling of custom dir and filename values in page definitions. This issue allows attackers to create files outside the intended build output directory by influencing SSG page definitions, potentially leading to unauthorized file creation with build user permissions. Developers and administrators using @quasar/app-vite should assess exposure in build configurations and verify page definition handling.
- Vendor
- quasarframework
- Product
- @quasar/app-vite
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Developers and administrators using @quasar/app-vite, especially those deriving SSG page definitions from external or untrusted content, or with compromised build configurations, should assess exposure in build configurations and verify page definition handling to prevent unauthorized file creation with build user permissions. This includes reviewing and validating SSG page definitions for potential directory traversal and verifying build configuration and
Why it matters
CVE-2026-106108 allows attackers to create files outside the intended build output directory by influencing SSG page definitions, potentially leading to unauthorized file creation with build user permissions.
- Potential creation of files outside intended build output directory
- Possible exploitation through influencing SSG page definitions
- Build user permissions could be leveraged for unauthorized file creation
Technical summary
The Quasar Framework's App Vite SSG page output paths can escape the configured distribution directory due to improper handling of custom dir and filename values in page definitions. This improper handling allows an attacker to create files outside the intended build output directory by influencing SSG page definitions. Existing files are protected by the SSG renderer's no-overwrite behavior, but new files and directories can be created with the permissions of the build user. The issue becomes relevant when an application derives SSG page definitions from external or otherwise untrusted content, or when build configuration is compromised.
Defensive priority
Assess exposure in build configurations and verify page definition handling
Recommended defensive actions
- Review and validate SSG page definitions for potential directory traversal
- Verify build configuration and permissions
- Update to version 3.3.0 or later of @quasar/app-vite
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The issue arises when SSG page definitions are derived from external or untrusted content, or when build configuration is compromised. Existing files are protected, but new files and directories can be created with build user permissions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106108 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106108
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106108 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106108
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Quasar Framework: App Vite SSG page output paths can escape the configured distribution director
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-vhhq-m2gm-rwc9.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/quasarframework/quasar/security/advisories/GHSA-vhhq-m2gm-rwc9
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/quasarframework/quasar/commit/cdd4daeec839215540221122763c7a17cd478abc
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/quasarframework/quasar
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/quasarframework/quasar/releases/tag/@quasar/app-vite-v3.1.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.