0.0
NA
CVE-2026-106108
Quasar Framework Path Traversal Vulnerability
Description

## Summary During an SSG build, page definitions returned by `getSsgPages()` can provide custom `dir` and `filename` values. The builder joined those values to `build.distDir` and wrote the generated page without verifying that the final destination remained inside the distribution directory. ## Details A page definition containing parent-directory traversal could cause the build to create a new HTML file outside `build.distDir`. An existing symlink below the distribution directory could also redirect a generated file or newly created directories outside the output tree. Quasar application configuration and SSG page definitions are trusted input by default, so this is not normally a remote file-write primitive. The issue becomes relevant when an application derives SSG page definitions from external or otherwise untrusted content, or when build configuration is compromised. Existing files are protected by the SSG renderer's no-overwrite behavior, but new files and directories can be created with the permissions of the build user. ## Impact An attacker able to influence an application's SSG page definitions could create files outside the intended build output directory during `quasar build -m ssg`. ## Remediation Resolve each page destination against the real `build.distDir`, reject absolute and parent-traversing paths, reject destinations that resolve to the output root where a file is expected, and verify existing ancestors after resolving symlinks.

INFO

Published Date :

Oct. 7, 2026, 4:14 p.m.

Last Modified :

Oct. 7, 2026, 4:14 p.m.

Remotely Exploit :

No

Source :

github-security-advisories
Affected Products

The following products are affected by CVE-2026-106108 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

Solution
Sanitize page definitions to prevent writing files outside the distribution directory.
  • Validate page definitions against build directory.
  • Reject absolute and parent-traversing paths.
  • Verify paths resolve within the output directory.
  • Prevent overwriting existing files.
References to Advisories, Solutions, and Tools
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-106108 is associated with the following CWEs:

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-106108 vulnerability anywhere in the article.

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.