Path traversal in Flatpak - #VU141400
Published: August 11, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to path traversal in the revokefs writer when processing repository data from unprivileged callers via symlink traversal between revokefs sessions. A local user can create a symlink between two revokefs sessions and retain a file descriptor to tamper with validated commit data to escalate privileges.
Exploitation requires an active local session and access to operations permitted by the system helper.