PT-2026-31024 · Flatpak+1 · Flatpak+1
CVE-2026-34078
·
Published
2026-04-07
·
Updated
2026-09-10
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Flatpak versions prior to 1.16.4
Description
Flatpak is a Linux application sandboxing and distribution framework. A flaw exists where the Flatpak portal accepts paths in the
sandbox-expose options that can be app-controlled symlinks pointing to arbitrary paths. Flatpak run mounts the resolved host path in the sandbox, potentially granting applications access to host files and enabling code execution in the host context. This allows a malicious or compromised application in flatpak format to bypass the established sandbox isolation, gain access to files in the main system, and execute arbitrary code outside of isolation.Recommendations
Update to Flatpak version 1.16.4 or later.
Exploit
Fix
DoS
RCE
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flatpak
Rocky Linux