CVE-2026-96276: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Red Hat Red Hat Enterprise Linux 10
If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal.
AI Analysis
Technical Summary
This vulnerability arises when a malicious SDK container declares an extension point with a crafted directory path. When a developer runs 'flatpak build-init --writable-sdk --sdk-extension' using that SDK, the path resolution function permits '..' traversal, enabling attacker-chosen files to be written outside the working directory. This improper limitation of pathname to a restricted directory (CWE-22) can allow unauthorized code execution, file modification, or reading of sensitive files. The issue affects flatpak as shipped with Red Hat Enterprise Linux 10 and is fixed in flatpak version 1.18.1.
Potential Impact
An attacker can write arbitrary files outside the intended directory, potentially overwriting critical files used for code execution or security mechanisms. This can lead to unauthorized code execution, bypass of security controls, exposure of sensitive data, or denial of service by corrupting essential files. The vulnerability affects system integrity, confidentiality, and availability.
Mitigation Recommendations
A fix is available in flatpak version 1.18.1. Users should upgrade to this version to remediate the vulnerability. Additionally, avoid using untrusted SDK containers for development or compilation to reduce risk.
CVE-2026-96276: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Red Hat Red Hat Enterprise Linux 10
Description
If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal.
CVSS v3.1
Score 9.8critical
Affected software
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 7
Red Hat
Red Hat Enterprise Linux 8
Red Hat
Red Hat Enterprise Linux 9
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises when a malicious SDK container declares an extension point with a crafted directory path. When a developer runs 'flatpak build-init --writable-sdk --sdk-extension' using that SDK, the path resolution function permits '..' traversal, enabling attacker-chosen files to be written outside the working directory. This improper limitation of pathname to a restricted directory (CWE-22) can allow unauthorized code execution, file modification, or reading of sensitive files. The issue affects flatpak as shipped with Red Hat Enterprise Linux 10 and is fixed in flatpak version 1.18.1.
Potential Impact
An attacker can write arbitrary files outside the intended directory, potentially overwriting critical files used for code execution or security mechanisms. This can lead to unauthorized code execution, bypass of security controls, exposure of sensitive data, or denial of service by corrupting essential files. The vulnerability affects system integrity, confidentiality, and availability.
Mitigation Recommendations
A fix is available in flatpak version 1.18.1. Users should upgrade to this version to remediate the vulnerability. Additionally, avoid using untrusted SDK containers for development or compilation to reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-22T20:42:35.875Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-96276","vendor":"Red Hat"}]
Threat ID: 6ab3edc8f7a7c54106f7e499
Added to database: 09/23/2026, 15:18:32 UTC
Last enriched: 09/23/2026, 15:32:47 UTC
Last updated: 09/24/2026, 01:57:04 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.