Executive brief
Briefcase is a tool used by developers to package Python projects into standalone applications. A vulnerability in the way it creates Windows installers (MSI files) can lead to insecure folder permissions on a user's computer. This allows a standard user to replace the application's files with malicious ones; if an administrator later runs the application, the attacker's code will execute with full administrative privileges.
Technical details
A vulnerability exists in the WXS templates used by Briefcase to generate Windows MSI installers. When an application is installed in a per-machine scope ('All Users'), the installation directory may inherit insecure permissions from its parent directory (CWE-732). A local, authenticated user with low privileges can exploit this to modify or replace application binaries. If a user with higher privileges (such as an administrator) subsequently executes the tampered binary, the attacker's code runs with elevated privileges. The issue was addressed by updating the 'briefcase-windows-app-template' and 'briefcase-windows-VisualStudio-template' to explicitly define secure directory permissions.
Affected products
- BeeWare briefcase >= 0.3.0, < 0.3.26
Timeline
- 2026-03-20: disclosed
- 2026-03-23: advisory: GitHub Advisory published
- 2026-03-26: other: NVD published