Executive brief
A vulnerability in the tool used to build Electron applications as AppImages can allow attackers to execute malicious code. If an application is launched from a directory where an attacker can write files (like a shared folder or /tmp), the application may inadvertently load and run a malicious library instead of a legitimate one. This could lead to a full compromise of the user's account and data on the affected system.
Technical details
The vulnerability is an uncontrolled search path element (CWE-427) in the AppRun script generated by app-builder-lib. When constructing environment variables like LD_LIBRARY_PATH, PATH, and XDG_DATA_DIRS, the script fails to handle cases where the existing variable is empty, resulting in a trailing colon (e.g., 'path/to/lib:'). In Linux dynamic linking, a trailing or empty colon entry resolves to the current working directory (CWD). A local attacker can achieve arbitrary code execution with the privileges of the victim by placing a malicious shared library in the CWD from which the AppImage is launched. This affects both the modern TypeScript-based runtime and the legacy Go-based app-builder-bin toolset. The issue is resolved in version 26.15.0.
Affected products
- electron-userland app-builder-lib < 26.15.0
Timeline
- 2026-06-16: disclosed: Initial disclosure in electron-builder repository
- 2026-06-16: patched: Fixed in app-builder-lib version 26.15.0
- 2026-07-24: advisory: GitHub Advisory published