PT-2026-31705 · Unknown · Flatpak-Builder

CVE-2026-39977

·

Published

2026-04-09

·

Updated

2026-04-21

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions flatpak-builder versions 1.4.5 through 1.4.7
Description flatpak-builder, a tool for building flatpaks from source, contains a flaw where the 'license-files' manifest key can be exploited to read arbitrary files from the host system and include them in the build output. This occurs because the validation of file paths does not fully resolve symlinks, allowing a crafted manifest and/or source to bypass security checks. The issue affects versions from 1.4.5 up to, but not including, 1.4.8.
Recommendations Update to flatpak-builder version 1.4.8 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39977
GHSA-6GM9-3G7M-3965
OPENSUSE-SU-2026:10590-1

Affected Products

Flatpak-Builder