Link following in Flatpak - CVE-2026-96284
Published: April 8, 2026 / Updated: September 28, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper link resolution in the OCI code paths of the system helper when importing OCI images under user control. A local user can provide a specially crafted OCI image with symlinks to disclose sensitive information.
Only systems with a system OCI repository configured are vulnerable.