Description
A flaw was found in flatpak-builder. This vulnerability allows an attacker to cause information disclosure by convincing a user or continuous integration (CI) system to process a crafted build manifest. By specifying local file Uniform Resource Identifiers (URIs) within source download definitions, the builder bypasses directory confinement checks. As a result, sensitive host files accessible to the build process can be read and incorporated into the build artifacts.
Published: 2026-10-08
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

If Flatpak packaging is not required on the system, remove the flatpak-builder package to eliminate exposure: # dnf remove flatpak-builder For development environments and continuous integration pipelines where flatpak-builder is necessary, apply the following operational controls: 1. Avoid processing build manifests from untrusted or unverified third-party sources. 2. Execute builds within isolated, ephemeral container or virtual machine environments where sensitive host files and credentials are not mounted or accessible. 3. Implement pre-build pipeline checks to reject manifests containing `file://` URI schemes in `type: file` or `type: archive` source definitions.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in flatpak-builder. This vulnerability allows an attacker to cause information disclosure by convincing a user or continuous integration (CI) system to process a crafted build manifest. By specifying local file Uniform Resource Identifiers (URIs) within source download definitions, the builder bypasses directory confinement checks. As a result, sensitive host files accessible to the build process can be read and incorporated into the build artifacts.
Title Flatpak-builder: local file exfiltration via `file
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-22
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-08T07:54:03.370Z

Reserved: 2026-10-08T06:59:41.785Z

Link: CVE-2026-107466

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T08:16:34.193

Modified: 2026-10-08T08:16:34.193

Link: CVE-2026-107466

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')