Skip to content
Noroxi

flatpak records

18 published records for vendor flatpak.

All records

18 records
  • Flatpak may allow access to files outside sandbox for certain apps

    CriticalCVSS 10.0No exploitEPSS 1%

    flatpak · flatpakAug 15, 2024

  • Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass.

    CriticalCVSS 9.0No exploitEPSS 2%

    flatpak · flatpakMar 26, 2019

  • Flatpak has a complete sandbox escape leading to host file access and code execution in the host context

    CriticalCVSS 9.3No exploitEPSS 1%

    flatpak · flatpakApr 7, 2026

  • Flatpak sandbox escape via spawn portal

    HighCVSS 8.8No exploitEPSS 1%

    flatpak · flatpakJan 14, 2021

  • CVE-2018-6560
    35Monitor

    In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to

    HighCVSS 8.8No exploitEPSS 0%

    flatpak · flatpakFeb 2, 2018

  • Permissions granted to applications can be hidden from the user at install time

    HighCVSS 8.6No exploitEPSS 1%

    flatpak · flatpakJan 12, 2022

  • Flatpak affected by arbitrary file deletion on the host filesystem

    HighCVSS 8.7No exploitEPSS 0%

    flatpak · flatpakApr 7, 2026

  • Flatpak vulnerable to a sandbox escape via RequestBackground portal due to bad argument parsing

    HighCVSS 8.4Proof of conceptEPSS 1%

    flatpak · flatpakApr 18, 2024

  • Sandbox escape via special tokens in .desktop file

    HighCVSS 8.2No exploitEPSS 2%

    flatpak · flatpakMar 11, 2021

  • CVE-2019-8308
    32Monitor

    Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a

    HighCVSS 8.2No exploitEPSS 0%

    flatpak · flatpakFeb 12, 2019

  • Sandbox bypass via recent VFS-manipulating syscalls

    HighCVSS 7.8No exploitEPSS 0%

    flatpak · flatpakOct 8, 2021

  • CVE-2017-9780
    31Monitor

    In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for ex

    HighCVSS 7.8No exploitEPSS 0%

    flatpak · flatpakJun 21, 2017

  • flatpak-builder has a path traversal leading to arbitrary file read on host when installing licence files

    HighCVSS 7.1No exploitEPSS 0%

    flatpak · flatpak-builderApr 9, 2026

  • flatpak-builder can access files outside the build directory.

    MediumCVSS 6.5No exploitEPSS 2%

    flatpak · flatpakJan 13, 2022

  • xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception

    MediumCVSS 6.8No exploitEPSS 0%

    flatpak · xdg-dbus-proxyApr 7, 2026

  • TIOCLINUX can send commands outside sandbox if running on a virtual console

    MediumCVSS 6.5No exploitEPSS 1%

    flatpak · flatpakMar 16, 2023

  • Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink

    MediumCVSS 6.3No exploitEPSS 0%

    flatpak · xdg-desktop-portalApr 10, 2026

  • Flatpak metadata with ANSI control codes can cause misleading terminal output

    MediumCVSS 4.3No exploitEPSS 1%

    flatpak · flatpakMar 16, 2023