Sceawere

Vulnerability Detail

CVE-2026-107466UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Flatpak-builder Local File Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
3h ago
Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
Attack Type
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in flatpak-builder. This vulnerability allows an attacker to cause information disclosure by convincing a user or continuous integration (CI) system to process a crafted build manifest. By specifying local file Uniform Resource Identifiers (URIs) within source download definitions, the builder bypasses directory confinement checks. As a result, sensitive host files accessible to the build process can be read and incorporated into the build artifacts.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-10-08T08:16:34.193Z",
  "pubdate": "2026-10-08T08:16:34.193Z",
  "executiveSummary": "A critical security flaw in flatpak-builder enables arbitrary local file disclosure through the processing of malformed build manifests.\nThe vulnerability is categorized as an improper restriction of file path access, allowing unauthorized reading of host-system files that should be out of scope.\nBy incorporating local file URIs within a source download definition, an attacker can bypass existing directory confinement checks during the build process.\nThe scope of impact includes the unauthorized extraction of sensitive host-based configuration files, credentials, or private data, which are subsequently bundled into the final build artifacts.\nThis vulnerability poses a significant risk to CI/CD pipelines and environments where users build third-party manifests, as a crafted manifest can be weaponized to exfiltrate host data without explicit user permission.\nNo authentication or network exposure is required for exploitation; the threat is triggered locally once the malicious manifest is processed by the build engine.\nSuccessful exploitation allows attackers to gain access to files accessible by the user executing the build, effectively escalating the impact of a seemingly innocuous manifest compilation.",
  "technicalDetails": "The vulnerability resides within the source management logic of flatpak-builder, specifically concerning the validation and sanitization of source download definitions. The application fails to adequately enforce confinement boundaries when parsing URIs provided in the build manifest.\nThe root cause is an insufficient validation mechanism for URI schemes, specifically regarding the handling of 'file://' URIs. When the builder processes a manifest containing a file-based URI, the path validation logic intended to confine the build process to a designated directory fails to detect or block references to arbitrary locations on the host filesystem.\nAttack flow begins with an attacker constructing a malicious build manifest. This manifest defines a source download that points to a sensitive target file path on the host system (e.g., /etc/shadow or ~/.ssh/id_rsa) using a local URI scheme. Upon execution, the flatpak-builder engine processes this source definition before applying standard sandbox or directory confinement constraints.\nBecause the builder component treats these URIs as legitimate sources for the application assembly process, it performs a read operation on the specified host file path. The requested file is then ingested by the builder as part of the build payload. Consequently, the sensitive data is incorporated into the resulting build artifact or container image generated by the process.\nThe exploitation does not require advanced network privileges or remote code execution; rather, it exploits the trust model of the builder utility. Any user or automated CI system that initiates a build on a malicious or untrusted manifest will inadvertently trigger the unauthorized file access. The impact is essentially the exfiltration of sensitive information from the host environment directly into the resulting binary or package, which the attacker can then inspect or distribute.\nThe vulnerability highlights a breakdown in input validation where user-provided URI inputs are processed with insufficient privilege isolation. Without strict enforcement of path sanitization or absolute restriction of file-based URI schemes during manifest ingestion, the builder remains vulnerable to directory traversal and local file inclusion tactics that circumvent established security barriers."
}
CVE-2026-107466: Flatpak-builder Local File Disclosure (MEDIUM Severity, CVSS: 6.1) | Sceawere