Path traversal in Flatpak - #VU141400

 

Path traversal in Flatpak - #VU141400

Published: August 11, 2026


Vulnerability identifier: #VU141400
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to path traversal in the revokefs writer when processing repository data from unprivileged callers via symlink traversal between revokefs sessions. A local user can create a symlink between two revokefs sessions and retain a file descriptor to tamper with validated commit data to escalate privileges.

Exploitation requires an active local session and access to operations permitted by the system helper.


Affected software

Flatpak

Remediation

Install security update from vendor's website.

Flatpak - update to 1.18.1

External References

Related Security Bulletins