{"id":"CVE-2026-96275","published":"2026-09-23T15:17:32.180","lastModified":"2026-09-25T18:17:34.003","description":"A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-22"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-96275","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539416","tags":[]},{"url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cg","tags":[]}],"exploitRefs":[{"url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cg","tags":[]}],"hasPoc":true,"ai":{"summary":"This flaw allows a malicious Flatpak repository to write attacker-controlled content to arbitrary locations on the host filesystem, potentially leading to privilege escalation or data loss.","exploitability":"Exploitation is moderately hard as it requires a compromised repository and the ability to manipulate file paths, but preconditions include system-level access.","blast_radius":"If exploited, the impact could be severe, as it allows for arbitrary code execution with root privileges.","remediation":"Disable the affected feature or restrict access to the Flatpak repositories to trusted sources.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","priv-escalation","flatpak","filesystem","symlink"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T08:56:25.410Z"}}