Back

HIGH

Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy directory export/bin

Published Sep 28, 2026

Description

A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed or upgraded. In system-wide installations, the deletion is performed as root.

Affected products

Remediation

Vendor solution

Avoid installing Flatpak apps from non-trusted publishers, particularly in system-wide deployments.

Red Hat statement

Red Hat estimates the CVSSv3.1 vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H from provided CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N. The attack requires user interaction and does not cross a security boundary, meaning the scope is unchanged.

Red Hat mitigation

Avoid installing Flatpak apps from non-trusted publishers, particularly in system-wide deployments.

Metrics

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 28, 2026
Updated Sep 28, 2026
Reserved Sep 23, 2026
CISA Vulnrichment
Updated Sep 28, 2026
NVD
Status Received
Modified Sep 28, 2026
Red Hat
Severity Important
Public date Sep 28, 2026