Path traversal in Flatpak - CVE-2026-97024

 

Path traversal in Flatpak - CVE-2026-97024

Published: September 28, 2026


Vulnerability identifier: #VU152567
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97024
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause data loss and loss of access to the system.

The vulnerability exists due to path traversal in files/etc handling in deploy directories when upgrading a malicious Flatpak app. A remote attacker can supply a malicious Flatpak app containing crafted files to overwrite system files and cause data loss and loss of access to the system.

User interaction is required to upgrade the malicious app.


Affected software

Flatpak

How to mitigate CVE-2026-97024

Install security update from vendor's website.

Flatpak - update to 1.18.4

External References

Related Security Bulletins