Description
Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate the authenticated user against the OCI repository. Only OCI-based sources (e.g. as used by Fedora) are affected; libostree-based sources such as Flathub are not.
No analysis available yet.
Remediation
Vendor Workaround
Use libostree repositories such as Flathub, or unauthenticated (public) OCI repositories.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6524-1 | flatpak security update |
References
History
Mon, 28 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate the authenticated user against the OCI repository. Only OCI-based sources (e.g. as used by Fedora) are affected; libostree-based sources such as Flathub are not. | |
| Title | Flatpak: flatpak: world-readable oci authentication token in system-helper cache path | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-378 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-28T20:57:01.080Z
Reserved: 2026-09-23T21:10:42.782Z
Link: CVE-2026-97025
No data.
Status : Received
Published: 2026-09-28T21:17:19.757
Modified: 2026-09-28T21:17:19.757
Link: CVE-2026-97025
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-378
Creation of Temporary File With Insecure Permissions
Debian DSA