Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.5

CVE-2026-96276: Flatpak build-init can write files outside project

CVE-2026-96276 · published 5 days ago
Summary

The Flatpak tool on Red Hat Enterprise Linux versions 7‑10 allows a specially crafted SDK container to place files outside the intended build directory when using the --writable-sdk and --sdk-extension options. This could let an attacker modify system files or insert malicious code. Protect your system by updating Flatpak to the latest version and avoid using writable SDKs from untrusted sources.

What to do
  • Update debian flatpak to version 1.16.6-1~deb13u2.
  • Update debian flatpak to version 1.18.1-1.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:Pro:18.04:LTS canonical flatpak All versions
– red hat red hat enterprise linux 10 All versions
– red hat red hat enterprise linux 7 All versions
– red hat red hat enterprise linux 8 All versions
– red hat red hat enterprise linux 9 All versions
Debian:12 debian flatpak All versions
Debian:13 debian flatpak < 1.16.6-1~deb13u2
Fix: upgrade to 1.16.6-1~deb13u2
Debian:14 debian flatpak < 1.18.1-1
Fix: upgrade to 1.18.1-1
Original advisory text
Flatpak: flatpak: arbitrary write in host context via flatpak build-init
If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal.
Severity
6.5 Medium
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published23 Sep 2026
Updated29 Sep 2026
First seen23 Sep 2026
Track software like this
Free during beta