CVE-2026-87723
Received Received - Intake

Path Hijacking Vulnerability in Google fuse-archive

Vulnerability report for CVE-2026-87723, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Google Inc.

Description

In Google fuse-archive versions prior to 1.24, an attacker who can prepend a directory to PATH or write a malicious binary to an attacker-controlled or writable directory appearing in PATH can hijack the execution pathway. This allows the attacker to execute arbitrary local code under the security context of the user running the fuse-archive process. The issue was partially mitigated in version 1.22 and fully resolved in 1.24 via refined selective PATH filtering.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
google fuse-archive to 1.24 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-426 The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-87723 affects Google fuse-archive versions before 1.24. An attacker who can modify the PATH environment variable or place a malicious binary in a writable directory in PATH could hijack the execution of fuse-archive. This would let the attacker run arbitrary local code with the privileges of the user running fuse-archive.

Detection Guidance

Check the version of fuse-archive installed on your system. If it is below 1.24, the system is vulnerable. Run: fuse-archive --version. If the version is prior to 1.24, update immediately to version 1.24 or later.

Impact Analysis

If you use a vulnerable version of fuse-archive, an attacker with local access could execute malicious code on your system. This could lead to data theft, system compromise, or further attacks depending on your user privileges. Upgrading to version 1.24 or later mitigates this risk.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially violating data confidentiality and integrity requirements in GDPR and HIPAA. Organizations must ensure systems are patched to prevent breaches that could result in regulatory penalties or loss of sensitive data.

Mitigation Strategies

Update fuse-archive to version 1.24 or later to fully resolve the issue. If updating is not immediately possible, ensure the PATH environment variable is sanitized by using the -o unsafe_path option cautiously or disabling external filters with -o noexternal.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87723. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart