Symlink Attack Vulnerability in Flatpak xdg-desktop-portal Software
CVE-2026-40354

2.9LOW

Key Information:

Vendor

Flatpak

Vendor
CVE Published:
11 April 2026

What is CVE-2026-40354?

The Flatpak xdg-desktop-portal software is susceptible to a symlink attack that allows any Flatpak application to delete files from the host system. This occurs through a flaw in the g_file_trash function that can be exploited to target and trash any file accessible to the Flatpak app, posing a significant risk to the integrity of user data. Users should update to the latest versions to mitigate this vulnerability and protect their systems from potential file destruction.

Affected Version(s)

xdg-desktop-portal 0 < 1.20.4

xdg-desktop-portal 1.21.0 < 1.21.1

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.