CyberRota Analysis
AI-GeneratedA path traversal vulnerability in Flatpak allows malicious applications to manipulate critical host system files, such as passwd and resolv.conf, during installation or upgrades, potentially leading to system compromise. This issue is particularly severe in system-wide installations, where the malicious app can execute actions with root privileges. Organizations using Flatpak for application deployment should prioritize patching this vulnerability to safeguard their systems from unauthorized access and data loss.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be emptied or replaced with a symlink when the app is installed or upgraded. In system-wide installations, the write is performed as root.