A AegiFlow
HIGHCVSS 7.8EPSS 0.1%

CVE-2026-54672

CVE-2026-54672 updated by NVD

Published
2026-07-24
Modified
2026-08-20
EPSS percentile
3%
Sources
github-advisory, nvd

Summary

electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary code by placing a malicious shared library in the directory from which the AppImage is launched. This issue has been fixed in version 26.15.0.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmapp-builder-lib26.15.0

Remediation: Upgrade to 26.15.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.