Disclosure summary
## Summary `@quasar/app-vite` recursively removes `build.distDir` before producing build artifacts. The configured path was made absolute, but it was not checked before removal. A configuration mistake could therefore target the project root, user home directory, a filesystem root, or another directory outside the project. ## Details The build command and mode builders passed the resolved output directory directly to `fs-extra` recursive removal. Existing symlink ancestors were not resolved before deletion either, so a path that appeared to be inside the project could operate on a directory outside it. `quasar.config` is trusted application code, and no attacker-controlled input reaches `build.distDir` by default. This issue is primarily destructive-build safety hardening. It can become a security boundary when build configuration is generated or influenced by less-trusted automation. ## Impact Running a normal Quasar build with an unsafe `build.distDir` can delete data accessible to the build user before compilation begins. ## Remediation Validate the effective deletion target before every artifact cleanup. Always reject filesystem roots, the user home directory and the project ro
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-q9mq-245r-4g93
Open original source · Updated Oct 07, 2026
Quasar Framework: App Vite build cleanup can recursively remove unsafe configured output directories
Source severity: MEDIUM / 4.1
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | @quasar/app-vite | >= 1.0.0, | 3.3.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T12:14:35-04:00
MODIFIED 2026-10-07T12:14:36-04:00
INGESTED 2026-10-08T12:05:11-04:00