CyberRota Analysis
AI-GeneratedA vulnerability exists in Flatpak that allows a malicious or compromised repository to write attacker-controlled content to arbitrary locations on the host filesystem, potentially with root privileges on system installations. This is due to improper handling of symlinks and insufficient sanitization of blob names, which can lead to directory traversal attacks. Organizations using Flatpak should prioritize addressing this issue to mitigate the risk of unauthorized file access and system compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.