PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106108 quasarframework CVE debrief

CVE-2026-106108 debrief: The Quasar Framework's App Vite SSG page output paths can escape the configured distribution directory due to improper handling of custom dir and filename values in page definitions. This issue allows attackers to create files outside the intended build output directory by influencing SSG page definitions, potentially leading to unauthorized file creation with build user permissions. Developers and administrators using @quasar/app-vite should assess exposure in build configurations and verify page definition handling.

Vendor
quasarframework
Product
@quasar/app-vite
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Developers and administrators using @quasar/app-vite, especially those deriving SSG page definitions from external or untrusted content, or with compromised build configurations, should assess exposure in build configurations and verify page definition handling to prevent unauthorized file creation with build user permissions. This includes reviewing and validating SSG page definitions for potential directory traversal and verifying build configuration and

Why it matters

CVE-2026-106108 allows attackers to create files outside the intended build output directory by influencing SSG page definitions, potentially leading to unauthorized file creation with build user permissions.

  • Potential creation of files outside intended build output directory
  • Possible exploitation through influencing SSG page definitions
  • Build user permissions could be leveraged for unauthorized file creation

Technical summary

The Quasar Framework's App Vite SSG page output paths can escape the configured distribution directory due to improper handling of custom dir and filename values in page definitions. This improper handling allows an attacker to create files outside the intended build output directory by influencing SSG page definitions. Existing files are protected by the SSG renderer's no-overwrite behavior, but new files and directories can be created with the permissions of the build user. The issue becomes relevant when an application derives SSG page definitions from external or otherwise untrusted content, or when build configuration is compromised.

Defensive priority

Assess exposure in build configurations and verify page definition handling

Recommended defensive actions

  • Review and validate SSG page definitions for potential directory traversal
  • Verify build configuration and permissions
  • Update to version 3.3.0 or later of @quasar/app-vite
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The issue arises when SSG page definitions are derived from external or untrusted content, or when build configuration is compromised. Existing files are protected, but new files and directories can be created with build user permissions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106108 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106108

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106108 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106108

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.