Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. app-builder-lib
  4. ›
  5. CVE-2026-54672

CVE-2026-54672: electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`

July 24, 2026

AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary code by placing a malicious shared library in the directory from which the AppImage is launched.

References

  • github.com/advisories/GHSA-7g7r-gx96-252g
  • github.com/electron-userland/electron-builder/commit/01b8ba979d1db44543e18d07b4ad94953deb10ea
  • github.com/electron-userland/electron-builder/releases/tag/electron-builder@26.15.0
  • github.com/electron-userland/electron-builder/security/advisories/GHSA-7g7r-gx96-252g
  • nvd.nist.gov/vuln/detail/CVE-2026-54672

Code Behaviors & Features

Detect and mitigate CVE-2026-54672 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 26.15.0

Fixed versions

  • 26.15.0

Solution

Upgrade to version 26.15.0 or above.

Impact 7.8 HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-427: Uncontrolled Search Path Element

Source file

npm/app-builder-lib/CVE-2026-54672.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:18:09 +0000.