Appimage is a lightweight software packaging and distribution framework that enables portable Linux applications; its vulnerability footprint centers on the core appimaged daemon and libappimage library components underlying the packaging and execution model. The recurring weakness classes, including download integrity validation and incomplete specification of security requirements, reflect the inherent risks of dynamic code loading and the critical role of cryptographic verification in the application distribution chain.
The number and severity of CVEs published that impact products developed by Appimage over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25265MEDIUM AppImage libappimage before 1.0.3 allows attackers to trigger an overwrite of a system-installed .desktop file by providing a .desktop file that contains Name= with path components | Dec 2, 2020 | 6.5 | 21 | NO | NO |
CVE-2020-25266MEDIUM AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid appimage. For example, it will accept a crafted mp3 file that contains an appimage, and | Dec 2, 2020 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Appimage.
Media articles that mention a CVE ID that affects a product developed by Appimage — matched by CVE ID, not by vendor name.