Impact
The vulnerability is a path‑traversal flaw in Flatpak's handling of the export/bin directory during app deployment. A malicious Flatpak application can use the flaw to delete any file outside its deployment directory when the app is installed or upgraded. In system‑wide installations the deletion happens with root privileges, allowing the attacker to remove critical system files or user data, potentially disrupting services or facilitating further compromise. This flaw is identified as CWE‑61.
Affected Systems
The issue affects Red Hat Enterprise Linux releases 7, 8, 9, and 10 on which Flatpak is installed. No specific sub‑version is singled out, so all current versions of those RHEL releases that ship Flatpak are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact, and while the EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog. Exploitation requires installing or upgrading a malicious Flatpak package, which means the attacker must first convince a user to add a non‑trusted app in a system‑wide deployment. If successful, the deletion is performed as root, giving the attacker the ability to destroy critical files. The risk is therefore significant for environments that use system‑wide Flatpak installations.
OpenCVE Enrichment
Debian DSA