Path traversal in Flatpak - #VU141403

 

Path traversal in Flatpak - #VU141403

Published: August 11, 2026


Vulnerability identifier: #VU141403
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose filenames from arbitrary host directories to sandboxed applications.

The vulnerability exists due to path traversal in host-side extension file access when processing extension content directories controlled by an installed extension. A remote user can place symlinks pointing to arbitrary host paths to disclose filenames from arbitrary host directories to sandboxed applications.

The issue is triggered when Flatpak checks the .ref lock marker file and iterates merge_dirs directories during application launch.


Affected software

Flatpak

Remediation

Install security update from vendor's website.

Flatpak - update to 1.18.1

External References

Related Security Bulletins