PatchSiren cyber security CVE debrief
CVE-2026-107466 Red Hat CVE debrief
A flaw in flatpak-builder allows an attacker to cause information disclosure by convincing a user or continuous integration (CI) system to process a crafted build manifest. By specifying local file Uniform Resource Identifiers (URIs) within source download definitions, the builder bypasses directory confinement checks. As a result, sensitive host files accessible to the build process can be read and incorporated into the build artifacts.
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for CI systems, developers using flatpak-builder, and administrators of environments where flatpak-builder is used should assess exposure and verify the integrity of their build environments.
Why it matters
CVE-2026-107466 allows information disclosure via crafted build manifests in flatpak-builder, impacting CI systems and users processing untrusted manifests. Defenders should verify and update instances, restrict access to sensitive files, and monitor for unusual patterns.
- Sensitive information disclosure through build artifacts.
- Potential for unauthorized access to host files.
- Need for verification of flatpak-builder instances and update to latest versions.
- Possible disruption of CI systems due to crafted build manifests.
Technical summary
The vulnerability in flatpak-builder allows an attacker to bypass directory confinement checks by specifying local file URIs within source download definitions in a crafted build manifest. This can lead to the reading of sensitive host files accessible to the build process and their incorporation into build artifacts. The vulnerability impacts CI systems and users processing untrusted build manifests, allowing for information disclosure. Defenders should prioritize verifying and updating flatpak-builder instances, especially in environments where CI systems or users process untrusted build manifests.
Defensive priority
Defenders should prioritize verifying and updating flatpak-builder instances, especially in environments where CI systems or users process untrusted build manifests.
Recommended defensive actions
- Verify and update flatpak-builder instances to the latest version.
- Restrict access to sensitive host files for CI systems and users processing build manifests.
- Implement additional monitoring for unusual file access patterns in build environments.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and source item provide details on the vulnerability in flatpak-builder, including its impact on information disclosure. The vulnerability allows an attacker to bypass directory confinement checks by specifying local file URIs within source download definitions in a crafted build manifest. This can lead to the reading of sensitive host files accessible to the build process and their incorporation into build artifacts. Defenders should verify the integrity of their build environments and monitor for unusual patterns. The
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107466 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107466
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107466 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107466
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Flatpak-builder: local file exfiltration via `file
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107466.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-107466
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.