Path traversal in Flatpak - CVE-2026-96282

 

Path traversal in Flatpak - CVE-2026-96282

Published: August 11, 2026 / Updated: September 28, 2026


Vulnerability identifier: #VU141403
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-96282
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose filenames from arbitrary host directories to sandboxed applications.

The vulnerability exists due to path traversal in host-side extension file access when processing extension content directories controlled by an installed extension. A remote user can place symlinks pointing to arbitrary host paths to disclose filenames from arbitrary host directories to sandboxed applications.

The issue is triggered when Flatpak checks the .ref lock marker file and iterates merge_dirs directories during application launch.


Affected software

Flatpak

How to mitigate CVE-2026-96282

Install security update from vendor's website.

Flatpak - update to 1.18.1

External References

Related Security Bulletins