Description
A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications using the extension. Additionally, unvalidated extension metadata can cause extension content to be mounted at unintended locations inside the sandbox.
No analysis available yet.
Remediation
Vendor Workaround
Avoid installing Flatpak extensions from non-trusted sources.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sun, 27 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications using the extension. Additionally, unvalidated extension metadata can cause extension content to be mounted at unintended locations inside the sandbox. | |
| Title | Flatpak: flatpak: extension metadata path traversal file existence oracle | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-59 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-27T21:53:43.645Z
Reserved: 2026-09-22T20:43:56.596Z
Link: CVE-2026-96282
No data.
Status : Received
Published: 2026-09-27T22:17:06.430
Modified: 2026-09-27T22:17:06.430
Link: CVE-2026-96282
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-59
Improper Link Resolution Before File Access ('Link Following')