Critical Vulnerability in Flatpak Allows Arbitrary File Write as Root
Article Content
- •CVE-2026-96275 allows arbitrary file write as root via compromised Flatpak repositories.
- •The vulnerability is due to improper symlink handling and path traversal in extract_extra_data.
- •Flatpak version 1.18.1 includes a patch; users should avoid untrusted sources.
A critical vulnerability (CVE-2026-96275) in Flatpak allows a malicious or compromised repository to write attacker-controlled content to arbitrary locations on the host filesystem, executing as root during system installs. The vulnerability arises from improper handling of symlinks and path traversal in the extract_extra_data function. Users must trust the repository to initiate an install or update, making the attack vector reliant on user action. Red Hat has issued a CVSS score of 7.5 (High) for this vulnerability, indicating significant risk. The issue has been patched in Flatpak version 1.18.1, and backports are available for LTS distributions. Users are advised to avoid installing Flatpak extensions from untrusted sources. The vulnerability was discovered by a researcher after a report from AISLE in collaboration with Red Hat.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…