Quasar Framework 是一个用于构建高性能 Vue.js 用户界面的框架。在 @quasar/icongenie 6.1.1 版本之前, 命令允许用户通过自行提供的配置文件传入文件夹路径和名称值,但并未将这些解析后的目标路径限制在 Quasar 项目目录内。具体而言, 将这些值与 (应用目录)拼接,而 仅要求输入为非空字符串,从而导致了目录遍历漏洞。如果开发人员运行了一个精心构造的配置文件,就可能使生成的图像内容被写入或覆盖到该用户有权写入的任意路径,进而可能篡改 Shell 启动文件、构建脚本或其他可
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| @quasar | icongenie | < 6.1.1 |
affected |
| quasarframework | quasar | < 2.22.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| quasarframework | quasar | < 2.22.0 | - |
|
| @quasar | icongenie | < 6.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106102 | 10.0 CRITICAL | Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead() |
| CVE-2026-106104 | 8.7 HIGH | Quasar Framework: Super-linear regex backtracking on User-Agent lets one request stall a Q |
| CVE-2026-106105 | 8.4 HIGH | Quasar Framework: Development TLS private keys are cached with overly permissive filesyste |
| CVE-2026-106107 | 8.3 HIGH | Quasar Framework: App Vite SSR and SSG nonce attributes are not safely constrained |
| CVE-2026-106106 | 7.1 HIGH | Quasar Framework: SSR/SSG dev error page discloses the full shell environment and its </sc |
| CVE-2026-106109 | 4.1 MEDIUM | Quasar Framework: App Vite build cleanup can recursively remove unsafe configured output d |
| CVE-2026-106101 | 3.1 LOW | Quasar Framework: DOM Clobbering in Quasar openURL() SafariViewController Integration Caus |
No comments yet