electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary code by placing a malicious shared library in the directory from which the AppImage is launched. This issue has been fixed in version 26.15.0.
History

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Electron-userland
Electron-userland app-builder-lib
Electron-userland electron-builder
Vendors & Products Electron-userland
Electron-userland app-builder-lib
Electron-userland electron-builder

Tue, 30 Jun 2026 22:45:00 +0000

Type Values Removed Values Added
Description electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary code by placing a malicious shared library in the directory from which the AppImage is launched. This issue has been fixed in version 26.15.0.
Title electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-06-30T22:15:03.264Z

Updated: 2026-06-30T22:15:03.264Z

Reserved: 2026-06-15T22:53:58.560Z

Link: CVE-2026-54672

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.