Information Disclosure Vulnerability in Flatpak Builder by Red Hat
CVE-2026-107466

6.1MEDIUM

What is CVE-2026-107466?

A vulnerability in Flatpak Builder allows attackers to exploit a flaw by convincing users or Continuous Integration (CI) systems to process a maliciously crafted build manifest. This can be achieved by using local file URIs in source download definitions, effectively bypassing directory confinement checks. As a result, potentially sensitive host files within the build process may be accessed and included in build artifacts, leading to unintentional information disclosure. Organizations using Flatpak Builder should assess their exposure to this vulnerability and take appropriate measures to mitigate risks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Found by AISLE in partnership with Red Hat.
.