Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
electron-userland electron-builder — electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .0014 3.5 —
AFFECTED
Product Versions Fixed
electron-builder < 26.15.0 – —
app-builder-lib < 26.15.0 – —
TIMELINE
Jun 15 Reserved by GitHub_M
Jun 30 EXPLOIT PUBLISHED — CVE-2026-54672 (electron-userland electron-builder). Public exploit reference added.
Jun 30 Published (CNA: GitHub_M)
Description
electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary code by placing a malicious shared library in the directory from which the AppImage is launched. This issue has been fixed in version 26.15.0.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| June 15, 2026 | Reserved | Reserved by GitHub_M |
| June 30, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-54672 (electron-userland electron-builder). Public exploit reference added. |
| June 30, 2026 | Published | Published (CNA: GitHub_M) |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| electron-userland | electron-builder | — | < 26.15.0 | — |
| electron-userland | app-builder-lib | — | < 26.15.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-54672 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.