https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-j5p8-jgjc-f3xv
If flatpak-builder is run against an untrusted manifest and the manifest
specifies `use-git-am: true`, a malicious module source can trigger
arbitrary code execution on the host system by adding a
`post-applypatch` hook.
I'm erring on the side of caution and reporting this as grave, but it
can maybe be downgraded to important since most people only build
Flatpak apps whose manifest they have written (or at least, had the
opportunity to audit) themselves. It's mainly a serious problem for
repository-as-a-service providers that accept untrusted apps for
building, like Flathub.
If this needs fixing in trixie, either with a DSA or in a point release,
I'd appreciate help. (Felix, would you be able to take this one?)
smcv