Path traversal in Flatpak - #VU141401

 

Path traversal in Flatpak - #VU141401

Published: August 11, 2026


Vulnerability identifier: #VU141401
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to path traversal in OCI archive extraction when extracting crafted OCI layer archives during install or update from an OCI remote. A remote attacker can serve a crafted OCI layer archive with an absolute hardlink target to disclose sensitive information.

System-wide installs running as root can expose sensitive host files such as /etc/shadow. Flatpak remotes using the default OSTree transport are not affected.


Affected software

Flatpak

Remediation

Install security update from vendor's website.

Flatpak - update to 1.18.1

External References

Related Security Bulletins