HomeCVE Intelligence › CVE-2026-54672
CVSS 7.8 HIGH Vulnerability

CVE-2026-54672: electron-updater: Uncontrolled search path elements within `AppImage` built by `app-build…

Summary AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added to the dynamic…

7.8CVSS Score
HIGHSeverity
NOCISA KEV
0.1%EPSS Score
VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-54672
Vendornpm
Affected Productapp-builder-lib
Vulnerability TypeVulnerability
CVSS Score7.8 (HIGH)
EPSS Score0.1% probability of exploitation in the next 30 days
Actively Exploited❌ No known exploitation
Patch StatusSee Vendor Advisory →
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via github_advisories)

🔬 Technical Analysis

#

Summary AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary code by placing a malicious shared library in the directory from which the AppImage is launched. This vulnerability is the same class as [CVE-2024-41817](https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8rxc-922v-phg8).

Details The vulnerability existed in two independent code paths within app-builder-lib (toolset 1.0.0) and through upstream dependency app-builder-bin (toolset 0.0.0).

Path 1 — Modern static runtime (AppRun generated by TypeScript) The `App

🎯 Known Indicators of Compromise

{"type":"url","value":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8rxc-922v-phg8).","confidence_score":0.82,"first_seen":"2026-07-24","source_count":1}

📚 Advisory References

⚡ DETECTION RULES AVAILABLE

Get CVE-2026-54672 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence