Link following in Flatpak - #VU141407
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote user to access arbitrary files on the host filesystem and potentially execute arbitrary code on the host.
The vulnerability exists due to improper link resolution in app data directory setup and bind mounts when creating and mounting attacker-controlled sandbox paths. A remote user can create a malicious symlink to redirect a bind-mounted directory to an arbitrary host location to access arbitrary files on the host filesystem and potentially execute arbitrary code on the host.
Exploitation requires a malicious sandboxed app.