Authentication Token Exposure in Flatpak by Red Hat
CVE-2026-97025

3.2LOW

What is CVE-2026-97025?

Flatpak has a security vulnerability where it writes the OCI repository authentication token with world-readable permissions in the system-helper's cache directory. This flaw permits any local user on a multi-user system to access the token, consequently allowing them to impersonate the authenticated user while interacting with the OCI repository. Only sources based on the OCI standard, such as those used by Fedora, are susceptible to this exposure. In contrast, libostree-based sources like Flathub remain unaffected.

References

CVSS V3.1

Score:
3.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank AISLE for reporting this issue.
.