VYPR

Flatpak

by Flatpak

Source repositories

CVEs (33)

  • CVE-2019-10063CriMar 26, 2019
    risk 0.59cvss 9.0epss 0.02

    Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass. Flatpak versions since 0.8.1 address CVE-2017-5226 by using a seccomp filter to prevent sandboxed apps from using the TIOCSTI ioctl, which could otherwise be used to inject…

  • CVE-2026-34078CriApr 7, 2026
    risk 0.58cvss 10.0epss 0.01

    Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This…

  • CVE-2026-96275HigSep 23, 2026
    risk 0.57cvss 8.8epss 0.00

    A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that…

  • CVE-2021-41133HigOct 8, 2021
    risk 0.57cvss 8.8epss 0.00

    Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can trick portals and other…

  • CVE-2018-6560HigFeb 2, 2018
    risk 0.57cvss 8.8epss 0.00

    In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.

  • CVE-2021-43860HigJan 12, 2022
    risk 0.53cvss 8.2epss 0.01

    Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the…

  • CVE-2017-9780HigJun 21, 2017
    risk 0.51cvss 7.8epss 0.00

    In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run the setuid executable…

  • CVE-2026-96280HigSep 27, 2026
    risk 0.49cvss 7.5epss —

    The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An…

  • CVE-2021-21261HigJan 14, 2021
    risk 0.47cvss 7.3epss 0.01

    Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a sandbox escape). This sandbox-escape…

  • CVE-2021-21381HigMar 11, 2021
    risk 0.46cvss 7.1epss 0.02

    Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which can be used by an attacker to gain access to files that would…

  • CVE-2019-8308HigFeb 12, 2019
    risk 0.46cvss 8.2epss 0.00

    Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

  • CVE-2026-96279MedSep 27, 2026
    risk 0.42cvss 6.5epss —

    A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For system-wide installs running as root, this includes…

  • CVE-2026-96276MedSep 23, 2026
    risk 0.42cvss 6.5epss 0.00

    If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is…

  • CVE-2026-34079HigApr 7, 2026
    risk 0.42cvss 7.5epss 0.00

    Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete…

  • CVE-2026-96808HigSep 23, 2026
    risk 0.41cvss 7.4epss 0.00

    In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivileged callers, validated file paths by rejecting literal .. components but did not prevent symlink traversal. A malicious local user in an active local session…

  • CVE-2026-90616HigSep 12, 2026
    risk 0.41cvss 7.4epss 0.00

    In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak creates a few app data directories (e.g.,…

  • CVE-2026-96281MedSep 27, 2026
    risk 0.40cvss 6.2epss —

    On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference…

  • CVE-2026-97024HigSep 29, 2026
    risk 0.39cvss 7.1epss —

    A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be emptied or replaced with a symlink when the app is…

  • CVE-2026-97023HigSep 28, 2026
    risk 0.39cvss 7.1epss —

    A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed or upgraded. In system-wide installations,…

  • CVE-2026-76925MedSep 4, 2026
    risk 0.38cvss 5.8epss 0.00

    A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before the OSTree repository validation within the…

Page 1 of 2