SCA: security update for @quasar/icongenie (GHSA-wmpw-j6qv-mw88)

high Tenable Self-Hosted Container Security Plugin ID 473716

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to
@quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values from a
user-supplied profile without constraining the resolved destination to the Quasar project directory.
icongenie/lib/utils/get-assets-files.js joined those values with appDir, while
icongenie/lib/utils/validate-profile-object.js required only non-empty strings, allowing parent-directory
traversal. A developer who runs a crafted profile can cause generated image content to be written or
overwritten at any path writable by that user, potentially modifying shell startup files, build scripts,
or other executable configuration. This issue is fixed in version 6.1.1. (CVE-2026-106103)

Solution

Update the @quasar/icongenie library and its related packages to version 6.1.1 or later.

See Also

https://github.com/advisories/GHSA-wmpw-j6qv-mw88

Plugin Details

Severity: High

ID: 473716

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/7/2026

Updated: 10/7/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.48

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.6

Temporal Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:C/A:C

CVSS Score Source: CVE-2026-106103

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/7/2026

Vulnerability Publication Date: 10/6/2026

Reference Information

CVE: CVE-2026-106103