← Vulnerability feed

Vulnerability record · CVE-2024-27303 · published 6 March 2024

CVE-2024-27303: Electron-builder untrusted search path vulnerability

Electron · Electron Builder

electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Windows and Linux. A vulnerability that only affects eletron-builder prior to 24.13.2 in Windows, the NSIS installer makes a system call to open cmd.exe via NSExec in the `.nsh` installer script. NSExec by default searches the current directory of where the installer is located before searching `PATH`. This means that if an attacker can place a malicious executable file named cmd.exe in the same folder as the installer, the installer will run the malicious file. Version 24.13.2 fixes this issue. No known workaround exists. The code executes at the installer-level before the app is present on the system, so there's no way to check if it exists in a current installer.

7.3 CVSS 3.1 High EPSS 0.28% · top 81.4% CWE-426 · Untrusted search pathCWE-427 · Uncontrolled search path element
7.3CVSS 3.1 base score
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Windows and Linux. A vulnerability that only affects eletron-builder prior to 24.13.2 in Windows, the NSIS installer makes a system call to open cmd.exe via NSExec in the `.nsh` installer script. NSExec by default searches the current directory of where the installer is located before searching `PATH`. This means that if an attacker can place a malicious executable file named cmd.exe in the same folder as the installer, the installer will run the malicious file. Version 24.13.2 fixes this issue. No known workaround exists. The code executes at the installer-level before the app is present on the system, so there's no way to check if it exists in a current installer.

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-27303 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2026-54673Electron builder-util-runtime information exposure vulnerabilityelectron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor.prepareRedirectUrlOptions) o…EPSS 0.41%7.8CVE-2026-54672Electron-builder uncontrolled search path element vulnerabilityelectron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder-lib could use an empty path …EPSS 0.19%7.5CVE-2024-39698Electron-builder improper certificate validation vulnerabilityelectron-updater allows for automatic updates for Electron apps. The file `packages/electron-updater/src/windowsExecutableCodeSignatureVerifier.ts` i…EPSS 0.43%7.8CVE-2012-1854Microsoft Office VBE6.dll Untrusted Search Path Privilege EscalationVBE6.dll in Microsoft Office 2003 SP3, 2007 SP2/SP3, 2010 Gold/SP1, Microsoft VBA, and the Summit Microsoft VBA SDK loads a library from an untrusted…KEVEPSS 21%analysed7.8CVE-2022-23748Audinate Dante mDNSResponder.exe DLL sideloading flawmDNSResponder.exe in Audinate's Dante Application Library improperly specifies how it loads a DLL, including the folder and conditions, allowing a ma…KEVEPSS 9.1%analysed7.8CVE-2022-22047Windows CSRSS elevation of privilege via untrusted search pathCVE-2022-22047 is an elevation of privilege flaw in the Windows Client Server Run-time Subsystem (CSRSS), classified as CWE-426 (untrusted search pat…KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2024-27303), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.