Path traversal in Flatpak - #VU141405
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to write attacker-controlled content to arbitrary locations on the host filesystem.
The vulnerability exists due to path traversal in extract_extra_data when extracting extra-data from a malicious or compromised Flatpak repository. A remote attacker can provide a repository containing a symlinked files entry to write attacker-controlled content to arbitrary locations on the host filesystem.
On system installs, the write occurs with root permissions.