Input validation error in Flatpak - #VU141398

 

Input validation error in Flatpak - #VU141398

Published: August 11, 2026


Vulnerability identifier: #VU141398
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to create files and directories outside the intended root directory.

The vulnerability exists due to improper input validation in the flatpak-system-helper DeployAppstream handling when processing a crafted architecture name in the \"arch\" parameter. A local user can supply a crafted architecture name to create files and directories outside the intended root directory.

Exploitation requires at least one OCI remote to be configured and an active local session.


Affected software

Flatpak

Remediation

Install security update from vendor's website.

Flatpak - update to 1.18.1

External References

Related Security Bulletins