Back to database
Schedule39High7.1VulnerabilityCVE-2026-97024No patch link observed

CVE-2026-97024 — A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certa…

Published Sep 29, 2026, 04:18 AM UTCIngested 10d agoSource NVD(cve-db)CVE-2026-97024

Description

A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be emptied or replaced with a symlink when the app is installed or upgraded. In system-wide installations, the write is performed as root.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
7.1

High severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

None

Privileges Required

UI

Required

User Interaction

S

Unchanged

Scope

C

None

Confidentiality

I

Low

Integrity

A

High

Availability