Symlink Attack Vulnerability in Flatpak xdg-desktop-portal Software
CVE-2026-40354
2.9LOW
What is CVE-2026-40354?
The Flatpak xdg-desktop-portal software is susceptible to a symlink attack that allows any Flatpak application to delete files from the host system. This occurs through a flaw in the g_file_trash function that can be exploited to target and trash any file accessible to the Flatpak app, posing a significant risk to the integrity of user data. Users should update to the latest versions to mitigate this vulnerability and protect their systems from potential file destruction.
Affected Version(s)
xdg-desktop-portal 0 < 1.20.4
xdg-desktop-portal 1.21.0 < 1.21.1
