<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Flatpak (All Versions Prior to Fix) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/flatpak-all-versions-prior-to-fix/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 06:25:28 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/flatpak-all-versions-prior-to-fix/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal Vulnerability in Flatpak App Deployment</title><link>https://feed.craftedsignal.io/briefs/2026-09-flatpak-path-traversal/</link><pubDate>Tue, 29 Sep 2026 06:25:28 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-flatpak-path-traversal/</guid><description>A path traversal vulnerability in Flatpak allows malicious applications to overwrite or replace critical host system files with symlinks during deployment, with root-level impacts for system-wide installations.</description><content:encoded><![CDATA[<p>CVE-2026-97024 is a path traversal vulnerability residing within the Flatpak packaging subsystem. During the deployment phase of application installation or updates, Flatpak fails to properly sanitize the handling of the files/etc directory. A malicious application, crafted to exploit this flaw, can navigate outside of its intended sandbox constraints and target sensitive files on the host filesystem. Observed targets include critical system configuration files such as /etc/passwd, /etc/group, /etc/machine-id, and /etc/resolv.conf.</p>
<p>When these operations occur during a system-wide Flatpak installation, the malicious actions are performed with root privileges, effectively allowing an attacker to clear the contents of sensitive files or replace them with malicious symlinks. This behavior leads to significant system instability, potential privilege escalation, or modification of security-critical system state. Defenders should prioritize auditing Flatpak installation sources and monitoring for anomalous file modifications originating from the flatpak system daemon.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the compromise of system-wide integrity. By manipulating files like /etc/passwd or /etc/resolv.conf, an attacker can disrupt system authentication or redirect network traffic. As these operations occur with root privileges, this represents a severe vulnerability for Linux systems utilizing system-wide Flatpak installations, particularly in multi-user or shared environments.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching all Flatpak installations to the latest version provided by your distribution as soon as the security update is available. Monitor host filesystem activity for unauthorized changes to critical configuration files in the /etc directory, specifically focusing on modifications where the initiating process is the flatpak-system-helper or related daemon.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>