CVE-2026-97025
Public on 2026-09-28
Modified on 2026-10-01
Description
When downloading apps or runtimes from an OCI repository that requires authentication, the OCI authentication token is written with the default permissions 0644. On multi-user systems this allows other local users to read the token file.
https://github.com/flatpak/flatpak/security/advisories/GHSA-7rvf-rqr3-43j4
https://github.com/flatpak/flatpak/security/advisories/GHSA-7rvf-rqr3-43j4
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | flatpak | Not Affected | ||
| Amazon Linux 2023 | flatpak | Pending Fix | ||
| Amazon Linux 2027 Preview | flatpak | Pending Fix | ||
| Amazon Linux 2023 | flatpak-builder | Not Affected | ||
| Amazon Linux 2027 Preview | flatpak-builder | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 3.2 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N |