flatpak is vulnerable to Path Traversal
33
Low Risk
When launching an application, Flatpak performs host-side file operations inside extension content directories using path APIs that follow symlinks without confinement, and it does not validate extension metadata fields for path traversal. A malicious extension can place symlinks or absolute and .. metadata values so that checking the .ref marker and iterating merge_dirs reveals which host paths exist and reflects host directory listings into the sandbox, and so that extension content is mounted at unintended locations. This discloses host filesystem structure to sandboxed apps and can override runtime directories. The fix rejects path traversal in extension metadata and uses confined host-side file access.
You are affected if you are using a version that falls within the vulnerable range and you install a Flatpak extension from an untrusted source.
flatpak is vulnerable to Path Traversal in versions 0.0.1 - 1.18.0.
Upgrade the flatpak library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant