flatpak is vulnerable to Path Traversal
62
Medium Risk
When flatpak build-init is run with --sdk-extensions or --base-extensions, it copies extension files into the build directory using a target path taken from the directory key in the extension metadata, resolved with an API that follows .. components. A malicious SDK that declares an extension point with a crafted directory value can cause files to be written outside the build tree, and existing files at the traversed path are deleted and replaced. This lets a crafted SDK write to arbitrary locations in the developer's host context. The fix uses fd-relative operations to prevent path traversal during extension copying.
You are affected if you are using a version that falls within the vulnerable range and you run flatpak build-init with --sdk-extensions or --base-extensions using an untrusted SDK.
flatpak is vulnerable to Path Traversal in versions 0.0.1 - 1.18.0.
Upgrade the flatpak library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant