Path traversal in Flatpak - #VU141397

 

Path traversal in Flatpak - #VU141397

Published: August 11, 2026


Vulnerability identifier: #VU141397
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to overwrite arbitrary files outside the working directory.

The vulnerability exists due to path traversal in flatpak build-init extension file copying when processing a malicious SDK container with crafted extension point metadata via --writable-sdk and --sdk-extension or extension copying options. A remote attacker can provide an SDK extension with a crafted directory path containing traversal sequences to overwrite arbitrary files outside the working directory.

Before copying, existing files at the traversed target path are deleted and replaced with the extension content.


Affected software

Flatpak

Remediation

Install security update from vendor's website.

Flatpak - update to 1.18.1

External References

Related Security Bulletins