Input validation error in Flatpak - #VU141398
Published: August 11, 2026
Vulnerability details
The vulnerability allows a local user to create files and directories outside the intended root directory.
The vulnerability exists due to improper input validation in the flatpak-system-helper DeployAppstream handling when processing a crafted architecture name in the \"arch\" parameter. A local user can supply a crafted architecture name to create files and directories outside the intended root directory.
Exploitation requires at least one OCI remote to be configured and an active local session.