CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-34078

Critical · CVSS 10.0

Flatpak — Symlink following sandbox escape leading to arbitrary file access and host code execution

CVSS
10.0
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-61, CWE-59

Description

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.

Search profile — drives PoC discovery

Symbols sandbox-exposeflatpak-portalflatpak runGHSA-cc2q-qc34-jprgsandbox_exposeportalsymlinkhost path mount
Keywords CVE-2026-34078Flatpak sandbox escapeFlatpak symlink portalsandbox-expose symlinkFlatpak portal symlink bypassGHSA-cc2q-qc34-jprgFlatpak arbitrary file accessFlatpak 1.16.4 patchCWE-59 FlatpakFlatpak host code execution PoC
Versions: < 1.16.4

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z