Path traversal in Flatpak - CVE-2026-97023
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to delete arbitrary files outside the deployment directory.
The vulnerability exists due to path traversal in the export/bin handling in deploy directories when upgrading a malicious Flatpak app. A remote attacker can supply a malicious Flatpak app with crafted paths to delete arbitrary files outside the deployment directory.
User interaction is required to upgrade the malicious app. For system-wide installations, file deletion is performed as root.