Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-96276

Опубликовано: 23 сент. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

If a malicious SDK container declares an extension point with a crafted directory path, and a developer runs flatpak build-init --writable-sdk --sdk-extension with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows .. traversal.

EPSS

Процентиль: 37%
0.00462
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
ubuntu
4 дня назад

security update

redhat
около 2 месяцев назад

If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal.

CVSS3: 9.8
debian
3 дня назад

If a malicious SDK container declares an extension point with a crafte ...

EPSS

Процентиль: 37%
0.00462
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22