{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aflatpakxdg-dbus-proxy/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:flatpak:xdg-dbus-proxy:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-94422"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["xdg-dbus-proxy (\u003c 0.1.9)"],"_cs_severities":["high"],"_cs_tags":["sandbox-escape","privilege-escalation","linux"],"_cs_type":"advisory","_cs_vendors":["Flatpak"],"content_html":"\u003cp\u003eCVE-2026-94422 involves an incorrect implementation of message filtering within xdg-dbus-proxy versions prior to 0.1.9. This utility, which is responsible for enforcing security boundaries for Flatpak applications, fails to correctly validate the reply serial number field on D-Bus messages. An attacker who controls a sandboxed application can inject a reply serial number into non-reply messages, tricking the proxy into incorrectly routing or authorizing messages that should have been blocked. This vulnerability enables a malicious or compromised application to escape the intended sandbox isolation, leading to arbitrary code execution on the underlying host system. While primarily impacting Flatpak environments, the tool is also utilized by other sandboxing frameworks such as Firejail, expanding the potential attack surface. Defenders should prioritize updating xdg-dbus-proxy to version 0.1.9 or later across all Linux systems hosting sandboxed applications.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in a full bypass of the sandbox security model. A successful exploit allows a malicious application to execute arbitrary code with the privileges of the user running the sandbox, potentially leading to unauthorized data access, persistence, or lateral movement within the environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade xdg-dbus-proxy to version 0.1.9 or later on all Linux distributions.\u003c/li\u003e\n\u003cli\u003eReview environments utilizing sandboxing frameworks like Flatpak or Firejail to ensure the host package repository reflects the patched version.\u003c/li\u003e\n\u003cli\u003eAudit logs for unexpected D-Bus communications originating from sandboxed process IDs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T14:25:29Z","date_published":"2026-10-02T14:25:29Z","id":"https://feed.craftedsignal.io/briefs/2026-10-xdg-dbus-proxy-bypass/","summary":"A vulnerability in xdg-dbus-proxy versions prior to 0.1.9 allows a compromised Flatpak application to bypass security filters and escape the sandbox via malformed D-Bus reply serials.","title":"Sandbox Escape via D-Bus Message Filtering Bypass in xdg-dbus-proxy","url":"https://feed.craftedsignal.io/briefs/2026-10-xdg-dbus-proxy-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:flatpak:xdg-Dbus-Proxy:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}