CVE-2026-97023

Summary

A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed or upgraded. In system-wide installations, the deletion is performed as root.

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-61: UNIX Symbolic Link (Symlink) Following

Workarounds

Avoid installing Flatpak apps from non-trusted publishers, particularly in system-wide deployments.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References