Skip to content
GHSA 5p67 Xh8x Rq54

GHSA 5p67 Xh8x Rq54

github.com • September 28, 2026

A path traversal vulnerability during app installation could be used by an attacker to delete files outside the deployment directory.

A malicious Flatpak app could arrange for an attacker-chosen file on the host system to be deleted when the app is upgraded. When installing Flatpak apps system-wide, the deletion would be done by root.

Fixed in 1.18.4 by commits

01cd7c4 "dir: Add fd-relative helpers for accessing deploy directories"

40f1265 "dir: Use fd-relative operations for export/bin removal during deploy"

That release also includes related hardening:

4682a91 "dir: Use fd-relative operations for app export during deploy"

efaa7c2 "dir: Use fd-relative operations in deploy_dir_is_locked"

47c8329 "run: Use deploy helper to open runtime files directory"

283aa55 "dir: Reuse app_files_dfd for .ref write during deploy"

556d6ef "dir: Use deploy helpers in apply_extra_data and flatpak_dir_deploy"

The changes required to address this vulnerability overlap with those required for GHSA-8xgq-v545-vgvf .

Avoid installing Flatpak apps from untrusted publishers, especially system-wide.

Extracted Entities

CWE Weaknesses (1)

Platforms (1)

Vulnerabilities (1)