Skip to content
Threat Feed
high advisory

Path Traversal Vulnerability in Flatpak App Deployment

A path traversal vulnerability in Flatpak allows malicious applications to overwrite or replace critical host system files with symlinks during deployment, with root-level impacts for system-wide installations.

CVE search metadata

CVE search record: CVE-2026-97024. Severity: high. CVSS: 7.1. KEV: no. Product: Flatpak (all versions prior to fix). Brief: Path Traversal Vulnerability in Flatpak App Deployment. Brief link: https://feed.craftedsignal.io/briefs/2026-09-flatpak-path-traversal/

CVE-2026-97024 is a path traversal vulnerability residing within the Flatpak packaging subsystem. During the deployment phase of application installation or updates, Flatpak fails to properly sanitize the handling of the files/etc directory. A malicious application, crafted to exploit this flaw, can navigate outside of its intended sandbox constraints and target sensitive files on the host filesystem. Observed targets include critical system configuration files such as /etc/passwd, /etc/group, /etc/machine-id, and /etc/resolv.conf.

When these operations occur during a system-wide Flatpak installation, the malicious actions are performed with root privileges, effectively allowing an attacker to clear the contents of sensitive files or replace them with malicious symlinks. This behavior leads to significant system instability, potential privilege escalation, or modification of security-critical system state. Defenders should prioritize auditing Flatpak installation sources and monitoring for anomalous file modifications originating from the flatpak system daemon.

Impact

Successful exploitation allows for the compromise of system-wide integrity. By manipulating files like /etc/passwd or /etc/resolv.conf, an attacker can disrupt system authentication or redirect network traffic. As these operations occur with root privileges, this represents a severe vulnerability for Linux systems utilizing system-wide Flatpak installations, particularly in multi-user or shared environments.

Recommendation

Prioritize patching all Flatpak installations to the latest version provided by your distribution as soon as the security update is available. Monitor host filesystem activity for unauthorized changes to critical configuration files in the /etc directory, specifically focusing on modifications where the initiating process is the flatpak-system-helper or related daemon.


Immediate actions

Update Flatpak installations to the latest patched version

IT Operations 48h

Threat Hunt

Detect file modifications to sensitive host /etc files by flatpak helper processes

T1068 high medium confidence hunt now

Data: Auditd or Sysmon for Linux process/file activity

Mitigations

Apply distribution-provided patches for Flatpak

immediate IT Operations

CVE-2026-97024