Skip to main content

Vendor archive

flatpak CVEs

Beta · best-effort

18 CVEs tagged to vendor flatpak4 Critical, 11 High, 2 Medium, 1 Low, 0 Unrated.

CVE-2026-40354

Published Apr 11, 2026

Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash.

CVSS 2.9 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-39977

Published Apr 9, 2026

flatpak-builder is a tool to build flatpaks from source. From 1.4.5 to before 1.4.8, the license-files manifest key takes an array of paths to user defined licence files relative…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34079

Published Apr 7, 2026

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app co…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-34078

Published Apr 7, 2026

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled s…

CVSS 9.3 · Critical
evidence mentions
20
Buzz score
49.5
Vendor/product tagsBeta · best-effort

CVE-2026-34080

Published Apr 7, 2026

xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=tr…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-42472

Published Aug 15, 2024

Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories cou…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-32462

Published Apr 18, 2024

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromi…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28101

Published Mar 16, 2023

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4, if an attacker publis…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28100

Published Mar 16, 2023

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4 contain a vulnerability s…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21261

Published Jan 14, 2021

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10063

Published Mar 26, 2019

Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass. Flatpak versions since 0.8.1 address CVE-2017-5226 by using a seccomp filter to…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-8308

Published Feb 12, 2019

Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

CVSS 8.2 · High

CVE-2018-6560

Published Feb 2, 2018

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whit…

CVSS 8.8 · High

CVE-2017-9780

Published Jun 21, 2017

In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The fil…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1