Path traversal in Flatpak - CVE-2026-97024
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause data loss and loss of access to the system.
The vulnerability exists due to path traversal in files/etc handling in deploy directories when upgrading a malicious Flatpak app. A remote attacker can supply a malicious Flatpak app containing crafted files to overwrite system files and cause data loss and loss of access to the system.
User interaction is required to upgrade the malicious app.