CVE-2026-97025

Summary

Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate the authenticated user against the OCI repository. Only OCI-based sources (e.g. as used by Fedora) are affected; libostree-based sources such as Flathub are not.

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-378: Creation of Temporary File With Insecure Permissions

Workarounds

Use libostree repositories such as Flathub, or unauthenticated (public) OCI repositories.

References