npm package report

Is @quasar/icongenie safe?

1 known vulnerability, worst severity HIGH.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


      cvss
      0.0
      high

      severity out of 10

      epss
      not scored

      chance of exploitation in 30 days

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — GHSA-wmpw-j6qv-mw88, the advisory selected below

      // 1 advisories

      GHSA-wmpw-j6qv-mw88

      HIGHCVE-2026-106103
      // vulnerability details

      File: icongenie/lib/utils/get-assets-files.js (line 35, absoluteName: join(appDir, asset.folder, asset.name)) Validation gap: icongenie/lib/utils/validate-profile-object.js (assetsSchema) — folder/name only checked with Joi.string().required().min(1), no restriction on .. sequences or absolute paths Entry point: icongenie/lib/runner/generate.js (generate(argv)) — profile.assets = userProfile.assets, loaded verbatim from a user-supplied JSON file via --profile

      // root cause

      icongenie generate --profile loads a JSON "profile" describing icon/splashscreen assets to generate, where each asset entry has a folder/name describing where the generated file should be written relative to the Quasar project directory (appDir). getAssetsFiles() builds the write target with join(appDir, asset.folder, asset.name). Node's path.join normalizes .. segments arithmetically and does not clamp the result to stay inside appDir. The only validation before this (validateProfileObject → Joi assetsSchema) checks that folder/name are non-empty strings, with no .. rejection and no containment check against appDir.

      A profile setting folder: "../../../../../../tmp/pwned-by-icongenie" sails through validation unmodified, and the generator writes attacker-influenced icon/splashscreen content to that path via a direct writeFile/sharp().toFile() call.

      // attack scenario
      • Attacker publishes a "ready-made Icon Genie profile" (gist, starter-kit repo, support forum attachment) that looks like a normal icon-generation config but includes an asset entry with a traversal folder.
      • A developer working on a Quasar project runs icongenie generate --profile malicious-profile.json (a normal, documented workflow) inside their project.
      • getAssetsFiles() resolves the write target outside the project directory; the generator writes attacker-controlled content to that path — e.g. planting/overwriting shell startup files, cron entries, or CI/build scripts.
      // impact
      • Type: CWE-22 Path Traversal / Arbitrary File Write
      • Auth required: No network auth — local CLI trust; requires the developer to run icongenie against a profile they didn't fully author/audit themselves
      • Consequence: Arbitrary file write/overwrite at any path the running user can write to, scoped by the number of .. segments — can lead to persistence (cron/shell rc file) or supply-chain-style code execution if the written file is later executed/sourced.
      // vulnerable code (icongenie/lib/utils/get-assets-files.js)
      export function getAssetsFiles(assets) {
        ...
        return list.map(({ tag, ...asset }) => {
          const file = {
            ...asset,
            relativeName: join(asset.folder, asset.name),
            absoluteName: join(appDir, asset.folder, asset.name)   // no containment check
          }
          ...
        })
      }
      // recommended fix
      import { resolve, sep } from 'node:path'
      
      const absoluteName = resolve(appDir, asset.folder, asset.name)
      
      if (absoluteName !== appDir && !absoluteName.startsWith(appDir + sep)) {
        fatal(`Profile asset escapes the project folder: "${asset.folder}/${asset.name}"`)
      }
      // verification

      Confirmed end-to-end on v2.21.1 by running the real, unmodified icongenie generate() function (from icongenie/lib/runner/generate.js) against a scratch Quasar project containing a crafted malicious-profile.json with "folder": "../../outside-target-marker". icongenie's own console output self-reported the traversal (Generated svg: ../../outside-target-marker/pwned-outside-project.svg), and the generated SVG file was independently verified on disk two directory levels outside the project folder.

      A fix branch (fix/icongenie-path-traversal-asset-folder) is ready with the minimal patch above. Re-running the same malicious profile against the patched code now aborts immediately with Profile asset escapes the project folder: "../../outside-target-marker/pwned-outside-project.svg" and writes nothing outside the project, while a legitimate profile (folder: "public/icons") continues to work exactly as before.

      // cvss v3.1 vector

      CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

      Attack vector
      Local
      Attack complexity
      Low
      Privileges required
      None
      User interaction
      Required
      Scope
      Unchanged
      Confidentiality
      None
      Integrity
      High
      Availability
      High

      Checked 2026-10-07 at 18:33 UTC. The most recent advisory here was published 2026-10-07. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.