Path traversal in Flatpak - #VU141406
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to write attacker-controlled content to arbitrary locations on the host filesystem.
The vulnerability exists due to path traversal in extract_extra_data when handling extra-data source names from commit metadata. A remote attacker can supply a crafted extra-data name containing .. components to write attacker-controlled content to arbitrary locations on the host filesystem.
On system installs, the write occurs with root permissions.