Flatpak · Flatpak · CVE-2026-97024
**Name of the Vulnerable Software and Affected Versions**
Flatpak versions prior to 1.18.4
**Description**
A path traversal issue exists in the way Flatpak handles the `files/etc` directory during app deployment. This allows a malicious application to empty or replace critical host system files, such as `passwd`, `group`, `machine-id`, or `resolv.conf`, with a symlink during installation or upgrade. In system-wide installations, these write operations are performed with root privileges, which can lead to a loss of system access.
**Recommendations**
Update to Flatpak version 1.18.4 or later.
Avoid installing applications from untrusted publishers for system-wide installations.