CVE-2026-107466
Received Received - Intake

Flatpak-builder Local File Disclosure via URI Manipulation

Vulnerability report for CVE-2026-107466, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: redhat-SADP

Description

A flaw was found in flatpak-builder. This vulnerability allows an attacker to cause information disclosure by convincing a user or continuous integration (CI) system to process a crafted build manifest. By specifying local file Uniform Resource Identifiers (URIs) within source download definitions, the builder bypasses directory confinement checks. As a result, sensitive host files accessible to the build process can be read and incorporated into the build artifacts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
redhat flatpak-builder to 1.4.4-1.el10 (inc)
flatpak flatpak_builder *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in flatpak-builder allows attackers to read sensitive host files by tricking users or CI systems into processing a malicious build manifest. The attacker uses local file URIs in the manifest to bypass directory confinement checks, enabling the build process to access and include host files in artifacts.

Detection Guidance

Check flatpak-builder version with 'flatpak-builder --version'. Inspect build manifests for 'file://' URIs in source definitions. Monitor build logs for error messages revealing file paths or checksums.

Impact Analysis

If exploited, this vulnerability could lead to unauthorized access to sensitive files on your system or CI environment. Attackers may exfiltrate confidential data by including it in build artifacts. The impact is limited to confidentiality and integrity within the build environment.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by exposing sensitive personal or health data during the build process. Organizations must ensure build environments are secure and manifests are trusted to avoid data leaks that violate regulatory requirements.

Mitigation Strategies

Avoid processing untrusted manifests. Reject manifests with 'file://' URIs in CI environments. Use isolated build setups. Update flatpak-builder to patched versions if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107466. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart