Impact
A malicious or compromised Flatpak repository can write attacker‑controlled data to arbitrary locations on the host filesystem. The vector is the extract_extra_data() routine, which follows symlinks and accepts blob names from xa.extra-data-sources without sanitising path traversal. On systems with Flatpak installed system‑wide the write occurs as root, giving the attacker full control over files, services, or binaries on the machine.
Affected Systems
Red Hat Enterprise Linux 7, 8, 9, and 10 running Flatpak. All users who install Flatpak extensions or use Flatpak repositories that are not fully trusted are at risk. The vulnerability exists in versions of Flatpak prior to v1.18.1 on these operating systems.
Risk and Exploitability
The CVSS score of 8.8 rates the vulnerability as high severity. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog. The attack most likely requires local or remote control of a Flatpak repository or the ability to install or update Flatpak extensions from a non‑trusted source. Once the vulnerable repository is used, the attacker can place arbitrary files or executables on the host with root privileges, enabling complete system compromise. The exploit does not depend on network exposure if the attacker already has local repository access, but can be triggered through a malicious extension distributed from an untrusted Flatpak ref or a compromised repository broker.
OpenCVE Enrichment