Description
A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host during the build process, resulting in arbitrary code execution with the privileges of the user running flatpak-builder.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Host Code Execution
Action: Apply Workaround
AI Analysis

Impact

Flatpak-builder contains a flaw that fails to disable Git hooks when applying patch sources with the 'use-git-am: true' setting. An attacker able to supply malicious source material that includes a Git post-applypatch hook can trigger that hook during the build process, leading to arbitrary code execution on the host system with the privileges of the user running flatpak-builder.

Affected Systems

The defect affects systems running Red Hat Enterprise Linux 8, 9, and 10 where flatpak-builder is used to process untrusted source code. While no specific flatpak-builder release numbers are cited, any installation of the tool on those operating systems is potentially vulnerable if the flagged option is enabled during a build.

Risk and Exploitability

The CVSS base score of 7.8 indicates moderate to high severity, yet the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting low exploitation probability so far. However, exploitation requires local access to a build environment or the ability to supply a malicious patch; an attacker with this capability could run arbitrary code with the builder user’s privileges. The recommended approach is to disable the 'use‑git‑am' flag for untrusted materials and to perform builds in isolated or disposable virtual machines until an official patch becomes available.

Generated by OpenCVE AI on September 18, 2026 at 01:47 UTC.

Remediation

Vendor Workaround

Avoid using use-git-am: true when processing untrusted manifests or source material. Where untrusted builds are required, perform builds inside disposable virtual machines or other isolated environments.


OpenCVE Recommended Actions

  • Disable the 'use-git-am' option when building from untrusted sources or manifests; this prevents Git hooks from executing during patch extraction.
  • Perform flatpak-builder builds inside disposable virtual machines or other isolated environments to contain any potential code execution.
  • Monitor Red Hat’s security advisories and update to any official flatpak-builder fix when it is released.

Generated by OpenCVE AI on September 18, 2026 at 01:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9

Thu, 17 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host during the build process, resulting in arbitrary code execution with the privileges of the user running flatpak-builder.
Title Flatpak-builder: host code execution via `git am` hook execution in patch source extraction (`use-git-am`)
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-94
CPEs cpe:/o:redhat:enterprise_linux:10
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-17T15:54:25.151Z

Reserved: 2026-09-07T05:35:25.012Z

Link: CVE-2026-86320

cve-icon Vulnrichment

Updated: 2026-09-17T15:42:29.021Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T08:17:02.200

Modified: 2026-09-18T19:06:08.407

Link: CVE-2026-86320

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:00:16Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')