{"id":"CVE-2026-54672","aliases":["GHSA-7g7r-gx96-252g"],"url":"https://o3.security/vulnerability/CVE-2026-54672","summary":"electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`","details":"### Summary\n\n`AppImage` targets built by `app-builder-lib` could use an empty path component when setting the `LD_LIBRARY_PATH` environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary code by placing a malicious shared library in the directory from which the `AppImage` is launched.\n\nThis vulnerability is the same class as [`CVE-2024-41817`](https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8rxc-922v-phg8).\n\n### Details\n\nThe vulnerability existed in two independent code paths within `app-builder-lib` (toolset `1.0.0`) and through upstream dependency `app-builder-bin` (toolset `0.0.0`).\n\n#### Path 1 — Modern static runtime (`AppRun` generated by TypeScript)\n\nThe `AppRun` script generated by `app-builder-lib` contained this line:\n\n```bash\nexport LD_LIBRARY_PATH=\"${APPDIR}/usr/lib:${LD_LIBRARY_PATH}\"\n```\n\nWhen `LD_LIBRARY_PATH` is not set in the environment at launch time, this evaluates to:\n\n```\n/path/to/app.AppDir/usr/lib:\n```\n\nThe trailing `:` is treated by the dynamic linker as an empty path component, which resolves to the current working directory. If an attacker can place a malicious shared library (e.g., `libfoo.so`) in the directory from which the `AppImage` is executed, that library will be loaded in place of the legitimate one, resulting in arbitrary code execution.\n\nThe same issue affected `PATH`, `XDG_DATA_DIRS`, and `GSETTINGS_SCHEMA_DIR` in the same script.\n\n```bash\nexport LD_LIBRARY_PATH=\"${APPDIR}/usr/lib${LD_LIBRARY_PATH:+:${LD_LIBRARY_PATH}}\"\n```\n\n#### Path 2 — Legacy FUSE2 toolset (`app-builder-bin`)\n\n`AppImage` targets built using the legacy FUSE2 toolset (`toolsets.appimage = \"0.0.0\"`) delegated `AppRun` script generation to the `app-builder-bin` Go binary, which contained the same vulnerable template:\n\nhttps://github.com/develar/app-builder/blob/7004925f95d8f034fc88d7e782c9aa7583debb8e/pkg/package-format/appimage/templates/AppRun.sh#L27\n\n### Impact\n\nAn attacker with the ability to write files to the directory from which a vulnerable `AppImage` is executed can cause arbitrary shared libraries to be loaded into the application process, resulting in arbitrary code execution with the privileges of the user running the `AppImage`.\n\n### Affected Versions\n\nThis was fully resolved in **`app-builder-lib@26.15.0`** (commit [`01b8ba979`](https://github.com/electron-userland/electron-builder/commit/01b8ba979), PR [#9829](https://github.com/electron-userland/electron-builder/pull/9829)) when `app-builder-bin` was removed from the dependency tree entirely and all AppImage construction was migrated to the TypeScript implementation.\n\n### Workarounds\n\nSet `LD_LIBRARY_PATH` to a non-empty value before launching the `AppImage`, so that the concatenation does not produce an empty path component. Alternatively, avoid running `AppImage` files from world-writable directories such as `/tmp`.","published":"2026-06-30T22:15:03.264Z","modified":"2026-08-20T03:53:40.619191249Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.00186,"percentile":0.08519,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"app-builder-lib","fixedVersion":"26.15.0"}],"fix":{"url":"https://github.com/electron-userland/electron-builder/commit/01b8ba979","label":"electron-userland/electron-builder@01b8ba9"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54672.json"},{"type":"ADVISORY","url":"https://github.com/electron-userland/electron-builder/security/advisories/GHSA-7g7r-gx96-252g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54672"},{"type":"FIX","url":"https://github.com/electron-userland/electron-builder/commit/01b8ba979"},{"type":"WEB","url":"https://github.com/electron-userland/electron-builder/commit/01b8ba979d1db44543e18d07b4ad94953deb10ea"},{"type":"PACKAGE","url":"https://github.com/electron-userland/electron-builder"},{"type":"WEB","url":"https://github.com/electron-userland/electron-builder/releases/tag/electron-builder@26.15.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-20T03:53:40.619191249Z"}}