https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-484h-v688-jq5j
There is no CVE for this, and upstream was unsure whether it's
CVE-worthy. Like CVE-2026-86320, it's primarily interesting for
repository-as-a-service providers that build untrusted or semi-trusted
source code, like Flathub.
I'll try to upload 1.4.11 to fix this and CVE-2026-86320 in unstable soon.
If this needs fixing in trixie, either with a DSA or in a point release,
I'd appreciate help. (Felix, would you be able to take this one?)
smcv