PT-2026-32056 · Unknown+2 · Xdg-Desktop-Portal+2
Published
2026-04-11
·
Updated
2026-05-20
·
CVE-2026-40354
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
xdg-desktop-portal versions prior to 1.20.4
xdg-desktop-portal versions prior to 1.21.1
Description
Flatpak xdg-desktop-portal allows any Flatpak application to move any file in the host context to the trash. This is possible through a symlink attack targeting the
g file trash() function.Recommendations
Update to version 1.20.4 or later.
Update to version 1.21.1 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Ubuntu
Xdg-Desktop-Portal