Path Traversal Vulnerability in Flatpak App Deployment
A path traversal vulnerability in Flatpak allows malicious applications to overwrite or replace critical host system files with symlinks during deployment, with root-level impacts for system-wide installations.
CVE search metadata
CVE search record: CVE-2026-97024. Severity: high. CVSS: 7.1. KEV: no. Product: Flatpak (all versions prior to fix). Brief: Path Traversal Vulnerability in Flatpak App Deployment. Brief link: https://feed.craftedsignal.io/briefs/2026-09-flatpak-path-traversal/
CVE-2026-97024 is a path traversal vulnerability residing within the Flatpak packaging subsystem. During the deployment phase of application installation or updates, Flatpak fails to properly sanitize the handling of the files/etc directory. A malicious application, crafted to exploit this flaw, can navigate outside of its intended sandbox constraints and target sensitive files on the host filesystem. Observed targets include critical system configuration files such as /etc/passwd, /etc/group, /etc/machine-id, and /etc/resolv.conf.
When these operations occur during a system-wide Flatpak installation, the malicious actions are performed with root privileges, effectively allowing an attacker to clear the contents of sensitive files or replace them with malicious symlinks. This behavior leads to significant system instability, potential privilege escalation, or modification of security-critical system state. Defenders should prioritize auditing Flatpak installation sources and monitoring for anomalous file modifications originating from the flatpak system daemon.
Impact
Successful exploitation allows for the compromise of system-wide integrity. By manipulating files like /etc/passwd or /etc/resolv.conf, an attacker can disrupt system authentication or redirect network traffic. As these operations occur with root privileges, this represents a severe vulnerability for Linux systems utilizing system-wide Flatpak installations, particularly in multi-user or shared environments.
Recommendation
Prioritize patching all Flatpak installations to the latest version provided by your distribution as soon as the security update is available. Monitor host filesystem activity for unauthorized changes to critical configuration files in the /etc directory, specifically focusing on modifications where the initiating process is the flatpak-system-helper or related daemon.
Immediate actions
Update Flatpak installations to the latest patched version
Threat Hunt
Detect file modifications to sensitive host /etc files by flatpak helper processes
Data: Auditd or Sysmon for Linux process/file activity
Mitigations
Apply distribution-provided patches for Flatpak
CVE-2026-97024