Path traversal in Flatpak - #VU141401
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in OCI archive extraction when extracting crafted OCI layer archives during install or update from an OCI remote. A remote attacker can serve a crafted OCI layer archive with an absolute hardlink target to disclose sensitive information.
System-wide installs running as root can expose sensitive host files such as /etc/shadow. Flatpak remotes using the default OSTree transport are not affected.