Link following in Flatpak - #VU141407

 

Link following in Flatpak - #VU141407

Published: August 11, 2026


Vulnerability identifier: #VU141407
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access arbitrary files on the host filesystem and potentially execute arbitrary code on the host.

The vulnerability exists due to improper link resolution in app data directory setup and bind mounts when creating and mounting attacker-controlled sandbox paths. A remote user can create a malicious symlink to redirect a bind-mounted directory to an arbitrary host location to access arbitrary files on the host filesystem and potentially execute arbitrary code on the host.

Exploitation requires a malicious sandboxed app.


Affected software

Flatpak

Remediation

Install security update from vendor's website.

Flatpak - update to 1.18.1

External References

Related Security Bulletins