Disclosure summary
## Vulnerability Details **File**: `icongenie/lib/utils/get-assets-files.js` (line 35, `absoluteName: join(appDir, asset.folder, asset.name)`) **Validation gap**: `icongenie/lib/utils/validate-profile-object.js` (`assetsSchema`) — `folder`/`name` only checked with `Joi.string().required().min(1)`, no restriction on `..` sequences or absolute paths **Entry point**: `icongenie/lib/runner/generate.js` (`generate(argv)`) — `profile.assets = userProfile.assets`, loaded verbatim from a user-supplied JSON file via `--profile ` ### Root Cause `icongenie generate --profile ` loads a JSON "profile" describing icon/splashscreen assets to generate, where each asset entry has a `folder`/`name` describing where the generated file should be written relative to the Quasar project directory (`appDir`). `getAssetsFiles()` builds the write target with `join(appDir, asset.folder, asset.name)`. Node's `path.join` normalizes `..` segments arithmetically and does not clamp the result to stay inside `appDir`. The only validation before this (`validateProfileObject` → Joi `assetsSchema`) checks that `folder`/`name` are non-empty strings, with no `..` rejection and no containment check against `appDir`. A p
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-wmpw-j6qv-mw88
Open original source · Updated Oct 07, 2026
Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Genie profile
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | @quasar/icongenie | < 6.1.1 | 6.1.1 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T12:14:14-04:00
MODIFIED 2026-10-07T12:14:15-04:00
INGESTED 2026-10-08T12:05:11-04:00