@quasar/icongenie is vulnerable to Path Traversal
73
High Risk
The @quasar/icongenie CLI bundles an image-processing dependency chain that reaches a legacy archive extractor through imagemin-pngquant and pngquant-bin. When the PNG optimizer cannot use its prebuilt binary, the install fallback extracts a bundled source archive with an extractor that can write files or symbolic links outside the intended directory. It also processes developer-supplied images with a version of sharp that inherits unpatched libvips memory-safety flaws. The fix removes the vulnerable PNG optimizer chain and upgrades sharp to a maintained release with indexed-PNG output.
You are affected if you are using a version that falls within the vulnerable range and you run Icon Genie on untrusted images or in an environment that builds the PNG optimizer from source.
@quasar/icongenie is vulnerable to Path Traversal in versions 2.0.0 - 6.1.1.
Upgrade the @quasar/icongenie library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant