Authentication Token Exposure in Flatpak by Red Hat
CVE-2026-97025
3.2LOW
What is CVE-2026-97025?
Flatpak has a security vulnerability where it writes the OCI repository authentication token with world-readable permissions in the system-helper's cache directory. This flaw permits any local user on a multi-user system to access the token, consequently allowing them to impersonate the authenticated user while interacting with the OCI repository. Only sources based on the OCI standard, such as those used by Fedora, are susceptible to this exposure. In contrast, libostree-based sources like Flathub remain unaffected.
References
CVSS V3.1
Score:
3.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank AISLE for reporting this issue.