Flatpak 1.18.4 fixes six security vulnerabilities
Flatpak 1.18.4 has been released, patching six newly disclosed vulnerabilities. The most serious, CVE-2026-97024 and CVE-2026-97023, let a malicious app overwrite or delete arbitrary files with elevated privileges.
- CVE-2026-97024: an app could overwrite files with an empty file or symlink
- CVE-2026-97023: arbitrary files could be deleted with elevated privileges
- CVE-2026-97025: OCI repository auth tokens were exposed to other local users
- CVE-2026-97029: a signal could terminate the user's desktop session
Read next
Security