Uncontrolled Search Path Element Affecting pipewire package, versions [0,]


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.13% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-PIPEWIRE-18017817
  • published19 Jul 2026
  • disclosed4 Jul 2026
  • creditUnknown

Introduced: 4 Jul 2026

CVE-2026-5674  (opens in a new tab)
CWE-427  (opens in a new tab)

How to fix?

There is no fixed version for pipewire.

Overview

Affected versions of this package are vulnerable to Uncontrolled Search Path Element via the PulseAudio compatibility layer when a malicious library is loaded from within a sandboxed process. An attacker can execute arbitrary code outside of the sandbox and compromise the host system by exploiting the ability to load untrusted libraries. This is only exploitable if the PulseAudio socket is accessible from the sandboxed environment or if module loading is permitted in the configuration.

Workaround

This vulnerability can be mitigated by restricting containerized applications from accessing the PulseAudio socket or writing to host-visible paths. Additionally, configure the service to prevent module loading by setting pulse.allow-module-loading = false in the configuration. Alternatively, restrict the dlopen() paths for module-ladspa-sink to trusted system directories such as /usr/lib/ladspa/ and /usr/lib64/ladspa/. Applying these changes may require restarting the service, which could impact audio functionality.

CVSS Base Scores

version 4.0
version 3.1