Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
If Flatpak packaging is not required on the system, remove the flatpak-builder package to eliminate exposure: # dnf remove flatpak-builder For development environments and continuous integration pipelines where flatpak-builder is necessary, apply the following operational controls: 1. Avoid processing build manifests from untrusted or unverified third-party sources. 2. Execute builds within isolated, ephemeral container or virtual machine environments where sensitive host files and credentials are not mounted or accessible. 3. Implement pre-build pipeline checks to reject manifests containing `file://` URI schemes in `type: file` or `type: archive` source definitions.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in flatpak-builder. This vulnerability allows an attacker to cause information disclosure by convincing a user or continuous integration (CI) system to process a crafted build manifest. By specifying local file Uniform Resource Identifiers (URIs) within source download definitions, the builder bypasses directory confinement checks. As a result, sensitive host files accessible to the build process can be read and incorporated into the build artifacts. | |
| Title | Flatpak-builder: local file exfiltration via `file | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-08T17:54:16.536Z
Reserved: 2026-10-08T06:59:41.785Z
Link: CVE-2026-107466
No data.
Status : Received
Published: 2026-10-08T08:16:34.193
Modified: 2026-10-08T08:16:34.193
Link: CVE-2026-107466
No data.
OpenCVE Enrichment
Updated: 2026-10-08T10:00:14Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')