CVE-2026-74859
Awaiting Analysis Awaiting Analysis - Queue

Path Traversal Vulnerability in GNOME Tweaks Shell Theme Installer

Vulnerability report for CVE-2026-74859, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: redhat-SADP

Description

The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using ../ path traversal, absolute paths, or symlink entries.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat gnome-tweaks *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-74859 is a path traversal vulnerability in the shell theme installer of gnome-tweaks. When users install themes via ZIP archives, the installer does not validate archive paths. This allows attackers to craft malicious themes that write files outside the intended ~/.themes directory using techniques like ../ path traversal, absolute paths, or symlinks.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized file modifications or suspicious theme installations. Monitor ~/.themes and system directories for unexpected files. Check gnome-tweaks logs for theme installation attempts. Use commands like 'find ~/.themes -type f -mtime -1' to find recently modified files or 'ls -la ~/.themes' to inspect directory contents.

Impact Analysis

This vulnerability could allow an attacker to overwrite critical system files, execute unauthorized code, or access sensitive data. Exploitation requires a user to install a malicious theme through gnome-tweaks, meaning no remote or automated attacks are possible without direct user interaction.

Mitigation Strategies

Avoid using gnome-tweaks to install gnome-shell themes until a patch is released. Do not install themes from untrusted sources. Monitor system files for unauthorized changes. Keep your system updated once a fix is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-74859. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart