File System Exposure in Flatpak Due to Malicious Extension by Red Hat
CVE-2026-96282

3.1LOW

What is CVE-2026-96282?

A vulnerability exists in the Flatpak framework that allows a malicious extension to access the host filesystem. This enables the extension to probe and determine the existence of files and directories at arbitrary paths. Furthermore, it can disclose sensitive directory listings to sandboxed applications, compromising their security. Additionally, unvalidated metadata within the extension can result in extension content being mounted at unintended and potentially dangerous locations inside the sandbox.

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Sebastian Wick as the original reporter.
.