GHSA-q9mq-245r-4g93

Suggest an improvement
Source
https://github.com/advisories/GHSA-q9mq-245r-4g93
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-q9mq-245r-4g93/GHSA-q9mq-245r-4g93.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q9mq-245r-4g93
Aliases
Published
2026-10-07T16:14:35Z
Modified
2026-10-07T16:30:06Z
Severity
  • 4.1 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Quasar Framework: App Vite build cleanup can recursively remove unsafe configured output directories
Details

Summary

@quasar/app-vite recursively removes build.distDir before producing build artifacts. The configured path was made absolute, but it was not checked before removal. A configuration mistake could therefore target the project root, user home directory, a filesystem root, or another directory outside the project.

Details

The build command and mode builders passed the resolved output directory directly to fs-extra recursive removal. Existing symlink ancestors were not resolved before deletion either, so a path that appeared to be inside the project could operate on a directory outside it.

quasar.config is trusted application code, and no attacker-controlled input reaches build.distDir by default. This issue is primarily destructive-build safety hardening. It can become a security boundary when build configuration is generated or influenced by less-trusted automation.

Impact

Running a normal Quasar build with an unsafe build.distDir can delete data accessible to the build user before compilation begins.

Remediation

Validate the effective deletion target before every artifact cleanup. Always reject filesystem roots, the user home directory and the project root; resolve existing symlink ancestors; require an explicit build.allowOutsideProjectDistDir opt-in for external output directories; and log the exact resolved target before removal.

Database specific
{
    "cwe_ids": [
        "CWE-22",
        "CWE-73"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T16:14:35Z",
    "nvd_published_at": "2026-10-06T18:16:52Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / @quasar/app-vite

Package

Name
@quasar/app-vite
View open source insights on deps.dev
Purl
pkg:npm/%40quasar/app-vite

Affected ranges

Type
SEMVER
Events
Introduced
1.0.0
Fixed
3.3.0

Database specific

last_known_affected_version_range
"<= 3.2.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-q9mq-245r-4g93/GHSA-q9mq-245r-4g93.json"