---
id: CVE-2026-96282
title: >-
  A malicious Flatpak extension can probe the host filesystem to determine what
  files and directories exist at arbitrary paths, and host directory listings
  can be disclosed to sandboxed applications using the extension
summary: >-
  A malicious Flatpak extension can probe the host filesystem to determine what
  files and directories exist at arbitrary paths, and host directory listings
  can be disclosed to sandboxed applications using the extension. Additionally,
  unval…
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-59
vendor: Red Hat
product: flatpak
affected:
  - flatpak (all versions)
  - flatpak (all versions)
  - flatpak (all versions)
  - flatpak (all versions)
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T22:17:06.430'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96282'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-96282'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2539422'
    label: secalert@redhat.com
  - url: 'https://github.com/flatpak/flatpak/security/advisories/GHSA-w69g-9x8j-7p8f'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T22:59:18.877Z'
---

## Overview

A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications using the extension. Additionally, unvalidated extension metadata can cause extension content to be mounted at unintended locations inside the sandbox.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
