flatpak is vulnerable to Path Traversal
76
High Risk
The Flatpak system helper's DeployAppstream method uses a caller-supplied architecture name to build filesystem paths without validating it. On systems with at least one OCI remote configured, a local user with an active session can pass a crafted architecture value containing path components to make the privileged helper create root-owned directories, a lock file, and an icons directory outside the intended location, with contents determined by the OCI remote. The fix validates remote name and architecture arguments before using them in paths.
You are affected if you are using a version that falls within the vulnerable range and at least one OCI remote is configured on the system.
flatpak is vulnerable to Path Traversal in versions 0.0.1 - 1.18.0.
Upgrade the flatpak library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant