Impact
The vulnerability allows an application running within a Flatpak sandbox to escape the confinement by creating symlinks that resolve to arbitrary host paths when passed to the sandbox‑expose options. Once the host paths are mounted, the app gains unrestricted read and write access to all files on the host system and may execute code in the host context. This represents a significant compromise of confidentiality, integrity, and availability of the host environment. The weakness aligns with path traversal (CWE‑59) and file inclusion (CWE‑61).
Affected Systems
All installations of Flatpak using the Flatpak portal preceding version 1.16.4 are affected. Users of the flatpak:flatpak product that rely on sandbox-expose feature must verify their current version and update. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 9.3 classifies the flaw as critical, and the EPSS score of 2% indicates a low probability of exploitation in the wild. Based on the description, it is inferred that the vulnerability allows a local attacker who can run a malicious Flatpak application to access host files and potentially execute code in the host context. It is not listed in KEV, suggesting it has not yet been widely exploited.
OpenCVE Enrichment
Debian DSA