Firejail · Firejail · CVE-2026-94422
**Name of the Vulnerable Software and Affected Versions**
xdg-dbus-proxy versions prior to 0.1.9
**Description**
An incorrect implementation of message filtering allows an attacker to bypass intended filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could exploit this to achieve arbitrary code execution outside its sandbox. This component is intended to be part of the sandbox boundary for Flatpak and is also utilized by other frameworks such as Firejail.
**Recommendations**
Update to version 0.1.9 or later.