PT-2026-99764 · Google · Fuse-Archive
CVSS v4.0
5.4
Medium
| Vector | AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Google fuse-archive versions prior to 1.24
Description
An attacker can hijack the execution pathway by prepending a directory to the
PATH environment variable or by writing a malicious binary to a writable directory that appears in the PATH. This allows for the execution of arbitrary local code using the security context of the user running the fuse-archive process. This issue is an Untrusted Search Path, which occurs when an application uses an external environment variable to locate an executable without properly validating the search path.Recommendations
Update to version 1.24.
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fuse-Archive