VYPR

fuse-archive

by Google

CVEs (1)

  • CVE-2026-87723MedSep 28, 2026
    risk 0.28cvss —epss —

    In Google fuse-archive versions prior to 1.24, an attacker who can prepend a directory to PATH or write a malicious binary to an attacker-controlled or writable directory appearing in PATH can hijack the execution pathway. This allows the attacker to execute arbitrary local code…