flatpak is vulnerable to Path Traversal
78
High Risk
flatpak's extra-data extraction resolves the files/extra location inside a checked-out commit tree using path operations that follow symlinks, and it builds child paths from an untrusted name in xa.extra-data-sources that can contain .. components. An untrusted repository can therefore redirect downloaded extra-data blobs through a symlink or traverse out of the intended directory to write to arbitrary host locations. On system installations this write happens as root. The fix validates the extra-data name and uses fd-relative path resolution to confine writes to the intended directory.
You are affected if you are using a version that falls within the vulnerable range and you install or update Flatpak content with extra-data from an untrusted repositories.
flatpak is vulnerable to Path Traversal in versions 0.0.1 - 1.18.0.
Upgrade the flatpak library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant