Path Traversal Vulnerability in Flatpak Affecting App Deployment
CVE-2026-97023
7.1HIGH
What is CVE-2026-97023?
A path traversal vulnerability has been identified in Flatpak's management of the export/bin directory during application deployment. This flaw allows a malicious Flatpak application to delete files specified by the attacker, potentially compromising system integrity, especially during installation or upgrades. In cases of system-wide deployment, this deletion action can be executed with root privileges, increasing the threat level significantly. Users should be aware of the risks associated with installing untrusted Flatpak applications and should apply necessary updates to mitigate this vulnerability.
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Sebastian Wick for reporting this issue.