Back

HIGH

Flatpak: flatpak: arbitrary write in root context via path traversal in deploy directory files/etc

Published Sep 29, 2026

Description

A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be emptied or replaced with a symlink when the app is installed or upgraded. In system-wide installations, the write is performed as root.

Affected products

Remediation

Vendor solution

Avoid installing Flatpak apps from untrusted publishers, especially system-wide.

Red Hat statement

Red Hat estimates the CVSSv3.1 vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H from provided CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N. The attack requires user interaction and does not cross a security boundary, meaning the scope is unchanged.

Red Hat mitigation

Avoid installing Flatpak apps from untrusted publishers, especially system-wide.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 29, 2026
Updated Sep 29, 2026
Reserved Sep 23, 2026
CISA Vulnrichment
Updated Sep 29, 2026
NVD
Status Received
Modified Sep 29, 2026
Red Hat
Severity Important
Public date Sep 28, 2026