Skip to content
GHSA Fqx6 Vh4p 42cg

GHSA Fqx6 Vh4p 42cg

github.com • September 23, 2026

A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem. On system installs, the write happens as root.

There are two vulnerabilities in extract_extra_data .

extract_extra_data resolves files/extra inside the checked-out commit tree using GFile path operations, which follow symlinks. If the files entry in the OSTree commit is a symlink (e.g., files -> /tmp ), the downloaded extra-data blobs are written at the symlink target instead.

extract_extra_data writes downloaded blobs to files/extra/ where comes from xa.extra-data-sources in the commit metadata. g_file_get_child resolves .. components, so a name like ../metadata escapes the extra/ directory.

On system installs, this code is executed with root permission.

The issue has been patched in version 1.18.1 by commits:

c42326c "utils: Add flatpak_cp_a_at, a fd-based flatpak_cp_a variant"

12a30ec "utils: Make flatpak_cp_a a wrapper around flatpak_cp_a_at"

eef9aae "dir: Validate extra-data name in pull_extra_data_to_bytes"

4266256 "dir: Use chaseat in extract_extra_data to prevent path traversal"

e805016 "dir: Use chaseat in apply_extra_data to prevent path traversal"

For LTS operating system distributions, backports of these changes are available in the flatpak-1.16.x branch. Please note that cherry-picked libglnx changes "chase: Add internal glnx_chaseat_full for a strategic callback" and "chase: Add glnx_chase_and_mkdirat" are also required.

Avoid installing Flatpak extensions from untrusted sources.

Found by @swick after investigating a report from AISLE in cooperation with Red Hat.

Extracted Entities

CWE Weaknesses (1)

Platforms (1)