CVE-2026-96276 is an improper path traversal vulnerability in Flatpak's SDK-extension handling within flatpak build-init. Extension-point metadata supplies a directory value used to determine where extension contents are copied. The vulnerable implementation resolves this value using a path-resolution function that accepts .. components, allowing a malicious SDK container to specify a directory path that escapes the intended build tree. Before copying extension contents, the resolved destination is recursively removed, allowing existing files at the traversed destination to be deleted and replaced with attacker-controlled content. Flatpak 1.18.0 and earlier are affected; the issue is fixed in Flatpak 1.18.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
flatpak build-init invocation. The operation can first remove the resolved target and then replace it with attacker-controlled content, potentially causing arbitrary file overwrite or deletion. Where build initialization is performed with elevated privileges, this can result in arbitrary root-context file writes and consequent privilege escalation, persistent compromise, or system integrity loss.If you can’t patch tonight, do this now.
flatpak build-init with elevated privileges unless operationally necessary.Patch, then assume compromise.
flatpak-1.16.x branch, including the required libglnx support changes.No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A path-traversal vulnerability (CWE-22) in Flatpak's SDK-extension handling. A malicious SDK container can use a crafted extension-point directory path to cause `flatpak build-init --writable-sdk --sdk-extension` to write attacker-selected files outside the intended working directory. The listed CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
An unpatched, network-accessible vulnerability tracked as CVE-2026-96276, affecting the Debian Linux 12.0 Flatpak package according to the listed CPE. It is rated critical by the provided CVSS v3 vector, with unauthenticated low-complexity network exploitation and high confidentiality, integrity, and availability impact.
A Flatpak arbitrary-root-file-write vulnerability caused by path traversal in the flatpak build-init command.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.