CVE-2026-97024 — A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certa…
Description
A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be emptied or replaced with a symlink when the app is installed or upgraded. In system-wide installations, the write is performed as root.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:HHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
Required
User Interaction
S
Unchanged
Scope
C
None
Confidentiality
I
Low
Integrity
A
High
Availability
References
Related threats
same CWE or vendorCVE-2026-106566 — ImageMagick is free and open-source software used for editing and manipulating digital images.
CVE-2026-106566 · 1d ago
CVE-2026-107174 — A flaw was found in source-to-image.
CVE-2026-107174 · 1d ago
CVE-2026-103435 — Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at wr…
CVE-2026-103435 · 1d ago
CVE-2026-106507 — Backstage is an open framework for building developer portals.
CVE-2026-106507 · 2d ago
CVE-2026-105712 — gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive.
CVE-2026-105712 · 3d ago
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections
OSV · 6d ago