← Back to search

CVE-2026-96276

6.5 MEDIUMpublic exploit available

Published 2026-09-23 · Updated 2026-09-27

AI risk analysis

Summary
The flaw allows a malicious SDK container to write attacker-chosen files outside the intended directory, posing a significant risk to system integrity.
Exploitability
Exploitation is moderately hard as it requires a malicious SDK and specific command execution. Developers must run `flatpak build-init` with the `--writable-sdk --sdk-extension` flags.
Blast radius
If exploited, this could lead to unauthorized data modification or loss, with potential impact on system security and data confidentiality.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the `flatpak build-init --writable-sdk --sdk-extension` functionality or restrict access to this feature.
rcesdkfile-write

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Weaknesses

CWE-22

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.