#1147701 flatpak-builder: GHSA-484h-v688-jq5j: Source URL scheme bypasses sandboxed mode protections across multiple source subtypes

Package:
flatpak-builder
Source:
flatpak-builder
Description:
Flatpak application building helper
Submitter:
Simon McVittie
Date:
2026-09-14 12:41:02 UTC
Severity:
normal
#1147701#5
Date:
2026-09-14 12:39:11 UTC
From:
To:
https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-484h-v688-jq5j

There is no CVE for this, and upstream was unsure whether it's
CVE-worthy. Like CVE-2026-86320, it's primarily interesting for
repository-as-a-service providers that build untrusted or semi-trusted
source code, like Flathub.

I'll try to upload 1.4.11 to fix this and CVE-2026-86320 in unstable soon.

If this needs fixing in trixie, either with a DSA or in a point release,
I'd appreciate help. (Felix, would you be able to take this one?)

    smcv