Local Code Execution Vulnerability in Google Fuse-Archive
CVE-2026-87723
5.4MEDIUM
What is CVE-2026-87723?
In Google Fuse-Archive prior to version 1.24, a vulnerability enables attackers to exploit the environment by manipulating the PATH variable. By prepending a directory or placing a malicious binary in an attacker-controlled directory that appears in the PATH, an unauthorized attacker could hijack the execution pathway. This exploit allows for the execution of arbitrary local code under the privileges of the user executing the Fuse-Archive process. This vulnerability was partially mitigated in version 1.22 and fully addressed in version 1.24 through improved selective PATH filtering.
Affected Version(s)
fuse-archive 0 < 1.24