CVE-2026-92162: Flatpak System Helper Path Traversal
Flatpak DeployAppstream arch traversal
A path traversal in the Flatpak system helper where an unvalidated arch string in DeployAppstream lets an active local user make the root helper create directories at an arbitrary path, chaining into a local root file write. Assigned CVE-2026-92162 and GHSA-v2gw-v9h5-9q4x.
- Status
- Assigned CVE
- Identifier
- CVE-2026-92162
- Touches
- Flatpak / Linux / Privilege Escalation / Path Traversal / D-Bus
- References
At a glance
The Flatpak system helper (flatpak-system-helper) runs as root on the system D-Bus and exposes DeployAppstream, a method any active local user can call without a password (polkit allow_active=yes). The handler validates the origin argument but passes the architecture string straight into a filesystem path. On the OCI branch that arch becomes a directory built with flatpak_build_file, which resolves .. segments lexically, so an arch of ../../../../../root/.ssh walks out of the appstream tree and g_mkdir_with_parents creates the chain as root.
It needs no admin rights, no prompt, and no working OCI server, only a local session and at least one OCI remote configured, which Fedora Workstation ships by default.
- Class: CWE-22, path traversal
- Component:
flatpak-system-helper, runs as root on the system D-Bus - Impact: Active local user creates root-owned directories at an arbitrary path
- Severity: High (per the advisory)
- Affected: Flatpak 1.18.0 and earlier
Because g_mkdir_with_parents creates parent directories, the bug supplies the missing piece for a second defect in Flatpak’s extra-data write path: one bug creates directories anywhere but writes no controlled content, the other writes controlled content but only where a directory already exists. Chained, they close the gap into a write-anywhere primitive and a path to local root.
Write-ups
I wrote two posts about this one. A technical breakdown of the bug covering the code path, the polkit boundary, the proof of concept, and the fix, and a longer story about how the hunt actually went, including the dead end and the twist at disclosure when one of the two bugs turned out to already be known.