{"id":"GHSA-wmpw-j6qv-mw88","summary":"Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Genie profile","details":"## Vulnerability Details\n\n**File**: `icongenie/lib/utils/get-assets-files.js` (line 35, `absoluteName: join(appDir, asset.folder, asset.name)`)\n**Validation gap**: `icongenie/lib/utils/validate-profile-object.js` (`assetsSchema`) — `folder`/`name` only checked with `Joi.string().required().min(1)`, no restriction on `..` sequences or absolute paths\n**Entry point**: `icongenie/lib/runner/generate.js` (`generate(argv)`) — `profile.assets = userProfile.assets`, loaded verbatim from a user-supplied JSON file via `--profile \u003cfile\u003e`\n\n### Root Cause\n`icongenie generate --profile \u003cfile\u003e` loads a JSON \"profile\" describing icon/splashscreen assets to generate, where each asset entry has a `folder`/`name` describing where the generated file should be written relative to the Quasar project directory (`appDir`). `getAssetsFiles()` builds the write target with `join(appDir, asset.folder, asset.name)`. Node's `path.join` normalizes `..` segments arithmetically and does not clamp the result to stay inside `appDir`. The only validation before this (`validateProfileObject` → Joi `assetsSchema`) checks that `folder`/`name` are non-empty strings, with no `..` rejection and no containment check against `appDir`.\n\nA profile setting `folder: \"../../../../../../tmp/pwned-by-icongenie\"` sails through validation unmodified, and the generator writes attacker-influenced icon/splashscreen content to that path via a direct `writeFile`/`sharp().toFile()` call.\n\n### Attack Scenario\n1. Attacker publishes a \"ready-made Icon Genie profile\" (gist, starter-kit repo, support forum attachment) that looks like a normal icon-generation config but includes an asset entry with a traversal `folder`.\n2. A developer working on a Quasar project runs `icongenie generate --profile malicious-profile.json` (a normal, documented workflow) inside their project.\n3. `getAssetsFiles()` resolves the write target outside the project directory; the generator writes attacker-controlled content to that path — e.g. planting/overwriting shell startup files, cron entries, or CI/build scripts.\n\n### Impact\n- **Type**: CWE-22 Path Traversal / Arbitrary File Write\n- **Auth required**: No network auth — local CLI trust; requires the developer to run icongenie against a profile they didn't fully author/audit themselves\n- **Consequence**: Arbitrary file write/overwrite at any path the running user can write to, scoped by the number of `..` segments — can lead to persistence (cron/shell rc file) or supply-chain-style code execution if the written file is later executed/sourced.\n\n### Vulnerable Code (`icongenie/lib/utils/get-assets-files.js`)\n```js\nexport function getAssetsFiles(assets) {\n  ...\n  return list.map(({ tag, ...asset }) =\u003e {\n    const file = {\n      ...asset,\n      relativeName: join(asset.folder, asset.name),\n      absoluteName: join(appDir, asset.folder, asset.name)   // no containment check\n    }\n    ...\n  })\n}\n```\n\n### Recommended Fix\n```js\nimport { resolve, sep } from 'node:path'\n\nconst absoluteName = resolve(appDir, asset.folder, asset.name)\n\nif (absoluteName !== appDir && !absoluteName.startsWith(appDir + sep)) {\n  fatal(`Profile asset escapes the project folder: \"${asset.folder}/${asset.name}\"`)\n}\n```\n\n### Verification\nConfirmed end-to-end on v2.21.1 by running the real, unmodified `icongenie generate()` function (from `icongenie/lib/runner/generate.js`) against a scratch Quasar project containing a crafted `malicious-profile.json` with `\"folder\": \"../../outside-target-marker\"`. icongenie's own console output self-reported the traversal (`Generated svg: ../../outside-target-marker/pwned-outside-project.svg`), and the generated SVG file was independently verified on disk two directory levels outside the project folder.\n\nA fix branch (`fix/icongenie-path-traversal-asset-folder`) is ready with the minimal patch above. Re-running the same malicious profile against the patched code now aborts immediately with `Profile asset escapes the project folder: \"../../outside-target-marker/pwned-outside-project.svg\"` and writes nothing outside the project, while a legitimate profile (`folder: \"public/icons\"`) continues to work exactly as before.","aliases":["CVE-2026-106103"],"modified":"2026-10-07T16:30:04.720529512Z","published":"2026-10-07T16:14:14Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-07T16:14:14Z","nvd_published_at":"2026-10-06T18:16:51Z","cwe_ids":["CWE-22","CWE-73"]},"references":[{"type":"WEB","url":"https://github.com/quasarframework/quasar/security/advisories/GHSA-wmpw-j6qv-mw88"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106103"},{"type":"WEB","url":"https://github.com/quasarframework/quasar/commit/87c89a80ec84f1eb7dbe258e5367161b0598ceb3"},{"type":"PACKAGE","url":"https://github.com/quasarframework/quasar"},{"type":"WEB","url":"https://github.com/quasarframework/quasar/releases/tag/@quasar/icongenie-v6.1.1"}],"affected":[{"package":{"name":"@quasar/icongenie","ecosystem":"npm","purl":"pkg:npm/%40quasar/icongenie"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-wmpw-j6qv-mw88/GHSA-wmpw-j6qv-mw88.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"}]}