boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-54672HIGH
electron-userland electron-builder — electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0014    3.5     —
AFFECTED
  Product           Versions     Fixed
  electron-builder  < 26.15.0 –  —
  app-builder-lib   < 26.15.0 –  —
TIMELINE
  Jun 15  Reserved by GitHub_M
  Jun 30  EXPLOIT PUBLISHED — CVE-2026-54672 (electron-userland electron-builder). Public exploit reference added.
  Jun 30  Published (CNA: GitHub_M)
CWE-427 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Analyzed

Description

electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary code by placing a malicious shared library in the directory from which the AppImage is launched. This issue has been fixed in version 26.15.0.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
June 15, 2026ReservedReserved by GitHub_M
June 30, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-54672 (electron-userland electron-builder). Public exploit reference added.
June 30, 2026PublishedPublished (CNA: GitHub_M)

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
electron-userlandelectron-builder< 26.15.0
electron-userlandapp-builder-lib< 26.15.0

Weaknesses

CWE-427

References (2)

Related

Authoritative record: CVE-2026-54672 at cve.org

Vendors: electron-userland

Weaknesses: CWE-427

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-54672 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.