Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash.
References
Configurations
Configuration 1 (hide)
|
History
27 Apr 2026, 23:11
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:flatpak:xdg-desktop-portal:*:*:*:*:*:*:*:* cpe:2.3:a:flatpak:xdg-desktop-portal:1.21.0:*:*:*:*:*:*:* |
|
| First Time |
Flatpak
Flatpak xdg-desktop-portal |
|
| References | () https://github.com/flatpak/xdg-desktop-portal/releases/tag/1.20.4 - Product | |
| References | () https://github.com/flatpak/xdg-desktop-portal/releases/tag/1.21.1 - Product | |
| References | () https://github.com/flatpak/xdg-desktop-portal/security/advisories/GHSA-rqr9-jwwf-wxgj - Vendor Advisory | |
| References | () https://www.openwall.com/lists/oss-security/2026/04/10/14 - Mailing List |
11 Apr 2026, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-11 01:16
Updated : 2026-06-17 10:45
NVD link : CVE-2026-40354
Mitre link : CVE-2026-40354
CVE.ORG link : CVE-2026-40354
JSON object : View
Products Affected
flatpak
- xdg-desktop-portal
CWE
CWE-61
UNIX Symbolic Link (Symlink) Following
