CVE-2026-100310 | GNU libextractor up to 1.15 Plugin Loading LIBEXTRACTOR_PREFIX untrusted search path

SecurityVulns

A vulnerability marked as critical has been reported in GNU libextractor up to 1.15. The affected element is an unknown function of the component Plugin Loading. This manipulation of the argument LIBEXTRACTOR_PREFIX causes untrusted search path.

The identification of this vulnerability is CVE-2026-100310. The attack can only be executed locally. There is no exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More