Path Traversal Vulnerability in Flatpak Affecting App Deployment
CVE-2026-97023

7.1HIGH

What is CVE-2026-97023?

A path traversal vulnerability has been identified in Flatpak's management of the export/bin directory during application deployment. This flaw allows a malicious Flatpak application to delete files specified by the attacker, potentially compromising system integrity, especially during installation or upgrades. In cases of system-wide deployment, this deletion action can be executed with root privileges, increasing the threat level significantly. Users should be aware of the risks associated with installing untrusted Flatpak applications and should apply necessary updates to mitigate this vulnerability.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Sebastian Wick for reporting this issue.
.