CVE-2026-82649: Nsis Uncontrolled Search Path Exec

Invoking system executables (e.g., taskkill, cmd, powershell) in NSIS without specifying an absolute system directory path (such as '$SYSDIR\') enables binary planting and search path hijacking, potentially leading to local privilege escalation.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Generic
greprules fetch cve-2026-82649-nsis-uncontrolled-search-path-exec --engine opengrep

Description

Invoking system executables (e.g., taskkill, cmd, powershell) in NSIS without specifying an absolute system directory path (such as '$SYSDIR\') enables binary planting and search path hijacking, potentially leading to local privilege escalation.