flatpak is vulnerable to Sandbox Escape
93
Critical Risk
Flatpak sets up per-app data directories such as /var/cache, /var/config and /var/tmp inside every sandbox on each app launch, using path components that the running application can control. The directory setup does not protect against symlinks, so a malicious sandboxed app can replace one of these paths with a symlink that is then passed to bwrap --bind. Because the kernel follows the symlink, an attacker-chosen host location is bind-mounted into the sandbox, giving the app arbitrary read and write access to the host filesystem and enabling code execution in the host context. The fix hardens the data directory and /var setup with fd-relative operations that resist symlink substitution.
You are affected if you are using a version that falls within the vulnerable range.
flatpak is vulnerable to Sandbox Escape in versions 0.0.1 - 1.18.0.
Upgrade the flatpak library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant