PT-2026-31705 · Unknown · Flatpak-Builder
Published
2026-04-09
·
Updated
2026-04-21
·
CVE-2026-39977
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
flatpak-builder versions 1.4.5 through 1.4.7
Description
flatpak-builder, a tool for building flatpaks from source, contains a flaw where the 'license-files' manifest key can be exploited to read arbitrary files from the host system and include them in the build output. This occurs because the validation of file paths does not fully resolve symlinks, allowing a crafted manifest and/or source to bypass security checks. The issue affects versions from 1.4.5 up to, but not including, 1.4.8.
Recommendations
Update to flatpak-builder version 1.4.8 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flatpak-Builder