{"id":"CVE-2026-96275","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-96275","summary":"A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write…","details":"A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.","published":"2026-09-23T15:17:32.180","modified":"2026-09-25T18:17:34.003","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-96275"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539416"},{"type":"WEB","url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cg"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-25T18:17:34.003"}}