<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 14:36:18 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-331689</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-331689</link>
      <description>EUVD-2026-331689</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-331689</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54672</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54672</link>
      <description>&lt;p&gt;electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary code by placing a malicious shared library in the directory from which the AppImage is launched. This issue has been fixed in version 26.15.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary code by placing a malicious shared library in the directory from which the AppImage is launched. This issue has been fixed in version 26.15.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54672</guid>
    </item>
    <item>
      <title>GHSA-7g7r-gx96-252g — electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7g7r-gx96-252g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: app-builder-lib&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`AppImage` targets built by `app-builder-lib` could use an empty path component when setting the `LD_LIBRARY_PATH` environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary code by placing a malicious shared library in the directory from which the `AppImage` is launched.&lt;/p&gt;
&lt;p&gt;This vulnerability is the same class as [`CVE-2024-41817`](https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8rxc-922v-phg8).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability existed in two independent code paths within `app-builder-lib` (toolset `1.0.0`) and through upstream dependency `app-builder-bin` (toolset `0.0.0`).&lt;/p&gt;
&lt;p&gt;#### Path 1 — Modern static runtime (`AppRun` generated by TypeScript)&lt;/p&gt;
&lt;p&gt;The `AppRun` script generated by `app-builder-lib` contained this line:&lt;/p&gt;
&lt;p&gt;```bash
export LD_LIBRARY_PATH=&amp;#34;${APPDIR}/usr/lib:${LD_LIBRARY_PATH}&amp;#34;
```&lt;/p&gt;
&lt;p&gt;When `LD_LIBRARY_PATH` is not set in the environment at launch time, this evaluates to:&lt;/p&gt;
&lt;p&gt;```
/path/to/app.AppDir/usr/lib:
```&lt;/p&gt;
&lt;p&gt;The trailing `:` is treated by the dynamic linker as an empty path component, which resolves to the current working directory. If an attacker can place a malicious shared library (e.g., `libfoo.so`) in the directory from which the `AppImage` is executed, that library will be loaded in place of the legitimate one, resulting in arbitrary code execution.&lt;/p&gt;
&lt;p&gt;The same issue affected `PATH`, `XDG_DATA_DIRS`, and `GSETTINGS_SCHEMA_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: app-builder-lib&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`AppImage` targets built by `app-builder-lib` could use an empty path component when setting the `LD_LIBRARY_PATH` environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary code by placing a malicious shared library in the directory from which the `AppImage` is launched.&lt;/p&gt;
&lt;p&gt;This vulnerability is the same class as [`CVE-2024-41817`](https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8rxc-922v-phg8).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability existed in two independent code paths within `app-builder-lib` (toolset `1.0.0`) and through upstream dependency `app-builder-bin` (toolset `0.0.0`).&lt;/p&gt;
&lt;p&gt;#### Path 1 — Modern static runtime (`AppRun` generated by TypeScript)&lt;/p&gt;
&lt;p&gt;The `AppRun` script generated by `app-builder-lib` contained this line:&lt;/p&gt;
&lt;p&gt;```bash
export LD_LIBRARY_PATH=&amp;#34;${APPDIR}/usr/lib:${LD_LIBRARY_PATH}&amp;#34;
```&lt;/p&gt;
&lt;p&gt;When `LD_LIBRARY_PATH` is not set in the environment at launch time, this evaluates to:&lt;/p&gt;
&lt;p&gt;```
/path/to/app.AppDir/usr/lib:
```&lt;/p&gt;
&lt;p&gt;The trailing `:` is treated by the dynamic linker as an empty path component, which resolves to the current working directory. If an attacker can place a malicious shared library (e.g., `libfoo.so`) in the directory from which the `AppImage` is executed, that library will be loaded in place of the legitimate one, resulting in arbitrary code execution.&lt;/p&gt;
&lt;p&gt;The same issue affected `PATH`, `XDG_DATA_DIRS`, and `GSETTINGS_SCHEMA_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7g7r-gx96-252g</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11200-1 — heroic-games-launcher-2.22.0-4.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11200-1</link>
      <description>&lt;p&gt;heroic-games-launcher-2.22.0-4.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;heroic-games-launcher-2.22.0-4.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11200-1</guid>
    </item>
  </channel>
</rss>
