Quasar Framework Path Traversal, Medium Severity -DC-Oct2026-2830

Listen to this Post

The Static Site Generation (SSG) process in Quasar Framework utilizes the `getSsgPages()` hook to collect custom route definitions, including destination properties such as directory path (dir) and file name (filename). During compilation, the renderer joins these user-supplied or content-derived values directly with the configured distribution directory path (build.distDir). Because the builder historically lacked strict path validation and boundary checking on the resolved target path, path traversal sequences (such as ../) contained within the page metadata could force file operations to escape the intended build output directory. Additionally, existing pre-created symbolic links within the distribution directory structure could be exploited to redirect directory creation or file writes outside the intended build tree. Under standard configurations, SSG definitions are treated as trusted inputs; however, in build environments where page definitions are dynamically constructed from external, untrusted, or user-supplied content sources, an attacker can write arbitrary static HTML files or create directories anywhere the build process user permissions allow. The engine’s default no-overwrite policy prevents modification of pre-existing system files, restricting impact to new file creation within accessible paths.

DailyCVE Form:

Platform: Quasar Framework
Version: Affected < 3.3.0
Vulnerability : Path Traversal
Severity: Medium
date: 2026-10-06

Prediction: Patch Released

Analytics Under Heading What Undercode Say

Commands and Code Analysis

The vulnerability manifests during the execution of the SSG compilation command:

quasar build -m ssg

In affected versions, page route definitions are exported via `/src-ssg/ssg-renderer.js` using defineSsgGetPages:

import { defineSsgGetPages } from 'q-app'
export const getSsgPages = defineSsgGetPages(async () => {
return [
{
route: '/about',
dir: '../../../tmp',
filename: 'malicious.html'
}
]
})

When joined directly via path.join(build.distDir, page.dir, page.filename), the traversal sequences resolve outside build.distDir, causing the output file to be written to an unintended system directory.

Exploitation Mechanics (Educational Purposes)

  1. An application dynamically fetches page route metadata from an untrusted or external source (e.g., CMS entries, database inputs).
  2. An injected route payload specifies a relative path containing directory traversal parameters in `dir` or filename.
  3. When `quasar build -m ssg` is executed, the SSG renderer resolves the destination path without verifying if the canonical path remains within build.distDir.
  4. The builder writes the newly rendered HTML file to the traversed target location with the privileges of the active build user.

Protection

To resolve this issue, apply the following controls:

  1. Upgrade Package Dependencies: Upgrade `@quasar/app-vite` to version `3.3.0` or higher where strict path canonicalization is enforced.
  2. Path Canonicalization: Validate and resolve target destinations against `fs.realpathSync(build.distDir)` prior to file write operations.
  3. Traversal Checking: Explicitly reject absolute paths, sequences containing .., or paths that resolve outside the output root.
  4. Symlink Validation: Verify ancestor directories after resolving symbolic links to ensure target paths do not traverse out of the distribution root.

Impact

An attacker capable of influencing SSG page definitions can create arbitrary HTML files and directory structures outside the configured build directory, limited only by the filesystem permissions of the build user process.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top