A flaw was found in flatpak-builder. This vulnerability allows an attacker to cause information disclosure by convincing a user or continuous integration (CI) system to process a crafted build manifest. By specifying local file Uniform Resource Identifiers (URIs) within source download definitions, the builder bypasses directory confinement checks. As a result, sensitive host files accessible to the build process can be read and incorporated into the build artifacts.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

If Flatpak packaging is not required on the system, remove the flatpak-builder package to eliminate exposure: # dnf remove flatpak-builder For development environments and continuous integration pipelines where flatpak-builder is necessary, apply the following operational controls: 1. Avoid processing build manifests from untrusted or unverified third-party sources. 2. Execute builds within isolated, ephemeral container or virtual machine environments where sensitive host files and credentials are not mounted or accessible. 3. Implement pre-build pipeline checks to reject manifests containing `file://` URI schemes in `type: file` or `type: archive` source definitions.

History

Thu, 08 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in flatpak-builder. This vulnerability allows an attacker to cause information disclosure by convincing a user or continuous integration (CI) system to process a crafted build manifest. By specifying local file Uniform Resource Identifiers (URIs) within source download definitions, the builder bypasses directory confinement checks. As a result, sensitive host files accessible to the build process can be read and incorporated into the build artifacts.
Title Flatpak-builder: local file exfiltration via `file
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-22
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-08T17:54:16.536Z

Reserved: 2026-10-08T06:59:41.785Z

Link: CVE-2026-107466

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T08:16:34.193

Modified: 2026-10-08T18:17:24.493

Link: CVE-2026-107466

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T10:00:14Z

Weaknesses