CVE-2026-54672Patch(electron / electron-builder)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch electron electron-builder systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary code by placing a malicious shared library in the directory from which the AppImage is launched. This issue has been fixed in version 26.15.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-427

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • electron-builder

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
electron-builder

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-01: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 107-01
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-54672 (CVSS 7.8) electron-updater <26.15.0 allows arbitrary code execution via malicious shared library in AppImage targets. Patch immediately to v26.15.0+ #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/mjeoanXk9M

    Post summary

    CVE‑2026‑54672 allows arbitrary code execution in electron-updater versions below 26.15.0 through a malicious shared library in AppImage; users are urged to upgrade to 26.15.0 or higher.

    0000053
    56 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelectronelectron-builder-node.js-

Explore more