Creation of Temporary File With Insecure Permissions in Flatpak - CVE-2026-97025
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to disclose OCI authentication tokens.
The vulnerability exists due to insecure file permissions in the OCI token cache path when downloading apps or runtimes from an authenticated OCI repository. A local user can read the token file to disclose OCI authentication tokens.
The issue is relevant to apps, runtimes, or extensions downloaded from OCI repositories.