Impact
The flaw lies in missing symlink protection for sandbox data directories that Flatpak creates on each app launch. A malicious or compromised sandboxed application can craft a symbolic link in one of these directories (e.g., /var/cache, /var/tmp). When Flatpak performs a bind mount with bwrap, the kernel resolves the symlink, mounting the target location inside the sandbox. This allows the sandboxed process to read or write arbitrary files on the host. With sufficient privileges the attacker can then execute code on the host, transforming the sandbox escape into full host compromise.
Affected Systems
Flatpak installations older than version 1.18.1 on any Linux system are affected. Any user who installs third the flaw because the attack requires only a corrupted or malicious app bundle. The vulnerable directories are those automatically created during app launch—/var/cache, /var/data, /var/config, and /var/tmp—whose path components can be controlled by the application.
Risk and Exploitability
The CVSS score of 7.4 places this vulnerability in the High severity range. The EPSS score of < 1% indicates a very low but nonzero likelihood of exploitation, and it is not listed in the CISA KEV catalog, suggesting no confirmed wild‑world exploitation at present. Nonetheless, the attack surface is broad: any untrusted Flatpak package can be deployed, and the kernel will honor user‑supplied symlinks in bind mounts. If exploited, the attacker achieves host file system read/write access and can execute arbitrary code, representing a severe confidentiality, integrity, and availability risk.
OpenCVE Enrichment
Debian DSA