Impact
Flatpak-builder contains a flaw that fails to disable Git hooks when applying patch sources with the 'use-git-am: true' setting. An attacker able to supply malicious source material that includes a Git post-applypatch hook can trigger that hook during the build process, leading to arbitrary code execution on the host system with the privileges of the user running flatpak-builder.
Affected Systems
The defect affects systems running Red Hat Enterprise Linux 8, 9, and 10 where flatpak-builder is used to process untrusted source code. While no specific flatpak-builder release numbers are cited, any installation of the tool on those operating systems is potentially vulnerable if the flagged option is enabled during a build.
Risk and Exploitability
The CVSS base score of 7.8 indicates moderate to high severity, yet the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting low exploitation probability so far. However, exploitation requires local access to a build environment or the ability to supply a malicious patch; an attacker with this capability could run arbitrary code with the builder user’s privileges. The recommended approach is to disable the 'use‑git‑am' flag for untrusted materials and to perform builds in isolated or disposable virtual machines until an official patch becomes available.
OpenCVE Enrichment