Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.5
CVE-2026-96276: Flatpak build-init can write files outside project
CVE-2026-96276 · published 5 days ago
Summary
The Flatpak tool on Red Hat Enterprise Linux versions 7‑10 allows a specially crafted SDK container to place files outside the intended build directory when using the --writable-sdk and --sdk-extension options. This could let an attacker modify system files or insert malicious code. Protect your system by updating Flatpak to the latest version and avoid using writable SDKs from untrusted sources.
What to do
- Update debian flatpak to version 1.16.6-1~deb13u2.
- Update debian flatpak to version 1.18.1-1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:Pro:18.04:LTS | canonical | flatpak | All versions |
| – | red hat | red hat enterprise linux 10 | All versions |
| – | red hat | red hat enterprise linux 7 | All versions |
| – | red hat | red hat enterprise linux 8 | All versions |
| – | red hat | red hat enterprise linux 9 | All versions |
| Debian:12 | debian | flatpak | All versions |
| Debian:13 | debian | flatpak |
< 1.16.6-1~deb13u2 Fix: upgrade to 1.16.6-1~deb13u2
|
| Debian:14 | debian | flatpak |
< 1.18.1-1 Fix: upgrade to 1.18.1-1
|
Original advisory text
Flatpak: flatpak: arbitrary write in host context via flatpak build-init
If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal.
References
- https://access.redhat.com/security/cve/CVE-2026-96276
- https://bugzilla.redhat.com/show_bug.cgi?id=2539418
- https://github.com/flatpak/flatpak/security/advisories/GHSA-8qxj-x646-phcm
- https://security-tracker.debian.org/tracker/CVE-2026-96276 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-96276 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-96276 Third Party Advisory
Severity
6.5
Medium
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published23 Sep 2026
Updated29 Sep 2026
First seen23 Sep 2026
Sources
CVE-2026-96276 · NVD
CVE-2026-96276 · MITRE
DEBIAN-CVE-2026-96276 · OSV
UBUNTU-CVE-2026-96276 · OSV
Track software like this
Free during beta