A path traversal vulnerability during app installation could be used by an attacker to delete files outside the deployment directory.
A malicious Flatpak app could arrange for an attacker-chosen file on the host system to be deleted when the app is upgraded. When installing Flatpak apps system-wide, the deletion would be done by root.
Fixed in 1.18.4 by commits
01cd7c4 "dir: Add fd-relative helpers for accessing deploy directories"
40f1265 "dir: Use fd-relative operations for export/bin removal during deploy"
That release also includes related hardening:
4682a91 "dir: Use fd-relative operations for app export during deploy"
efaa7c2 "dir: Use fd-relative operations in deploy_dir_is_locked"
47c8329 "run: Use deploy helper to open runtime files directory"
283aa55 "dir: Reuse app_files_dfd for .ref write during deploy"
556d6ef "dir: Use deploy helpers in apply_extra_data and flatpak_dir_deploy"
The changes required to address this vulnerability overlap with those required for GHSA-8xgq-v545-vgvf .
Avoid installing Flatpak apps from untrusted publishers, especially system-wide.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
