{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aflatpakflatpak/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-96275"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Flatpak"],"_cs_severities":["high"],"_cs_tags":["linux","flatpak","vulnerability","path-traversal"],"_cs_type":"advisory","_cs_vendors":["Flatpak"],"content_html":"\u003cp\u003eCVE-2026-96275 identifies a critical flaw in Flatpak's handling of extra data sources, specifically within the extract_extra_data() function. The vulnerability stems from two combined weaknesses: the resolution of files/extra paths that incorrectly follow symbolic links and the failure to sanitize blob names defined in the xa.extra-data-sources configuration. An attacker operating a malicious or compromised Flatpak repository can use directory traversal sequences, such as '..', within these blob names to escape intended directories and write content to arbitrary locations on the host. When Flatpak is utilized for system-wide installations, this process executes with root privileges, allowing an attacker to overwrite system files, place unauthorized binaries, or modify configuration files. This impacts any system relying on Flatpak for application management where untrusted repositories might be configured.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary file creation or modification on the host system. In scenarios involving system-wide Flatpak installations, this results in full root-level compromise of the host filesystem. This vulnerability affects Linux systems leveraging Flatpak for software distribution and management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for administrators and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit configured Flatpak remotes and repositories to ensure only trusted sources are authorized.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized additions of new Flatpak repositories on production systems.\u003c/li\u003e\n\u003cli\u003ePrioritize updates to the Flatpak runtime and core binaries as soon as security patches are released by upstream maintainers.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring (FIM) on critical system directories, particularly those frequently targeted for persistent modifications, to detect anomalous file writes occurring from the flatpak binary or associated helper processes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T02:45:51Z","date_published":"2026-09-24T02:45:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-flatpak-traversal/","summary":"A vulnerability in Flatpak's extract_extra_data() allows malicious repositories to perform path traversal and write arbitrary files to the host filesystem, potentially leading to root access on system-wide installations.","title":"Path Traversal and Arbitrary File Write in Flatpak","url":"https://feed.craftedsignal.io/briefs/2026-09-flatpak-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}