AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-106109.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 4.1CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

## Summary `@quasar/app-vite` recursively removes `build.distDir` before producing build artifacts. The configured path was made absolute, but it was not checked before removal. A configuration mistake could therefore target the project root, user home directory, a filesystem root, or another directory outside the project. ## Details The build command and mode builders passed the resolved output directory directly to `fs-extra` recursive removal. Existing symlink ancestors were not resolved before deletion either, so a path that appeared to be inside the project could operate on a directory outside it. `quasar.config` is trusted application code, and no attacker-controlled input reaches `build.distDir` by default. This issue is primarily destructive-build safety hardening. It can become a security boundary when build configuration is generated or influenced by less-trusted automation. ## Impact Running a normal Quasar build with an unsafe `build.distDir` can delete data accessible to the build user before compilation begins. ## Remediation Validate the effective deletion target before every artifact cleanup. Always reject filesystem roots, the user home directory and the project ro

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-q9mq-245r-4g93

Open original source · Updated Oct 07, 2026

Quasar Framework: App Vite build cleanup can recursively remove unsafe configured output directories

Source severity: MEDIUM / 4.1

EcosystemPackageAffected rangeFirst patched
npm@quasar/app-vite>= 1.0.0,3.3.0

Original records & references

PUBLISHED 2026-10-07T12:14:35-04:00
MODIFIED 2026-10-07T12:14:36-04:00
INGESTED 2026-10-08T12:05:11-04:00