Flatpak 1.18.4 Fixes Six Security Vulnerabilities, Two of Them File Destruction Bugs
Flatpak 1.18.4 was released on September 28 as a security update fixing six newly disclosed vulnerabilities, plus two more in the bundled D-Bus proxy. It arrives six days after 1.18.3, and a month after 1.18.1’s sandbox escape fixes.
The six CVEs
| CVE | What it allowed |
|---|---|
| CVE-2026-97024 | A malicious app could, during installation, overwrite arbitrary files with an empty file or a symlink |
| CVE-2026-97023 | A malicious app could delete arbitrary files with elevated privileges |
| CVE-2026-97025 | Authentication tokens for private OCI repositories could be read by other local users |
| CVE-2026-97026 | Temporary repository directories under /var/tmp/flatpak-cache-* had permissions that were too loose |
| CVE-2026-97027 | Crafted .desktop and D-Bus .service files could cause denial of service or unintended interaction with host services. Flatpak now filters them against an allowlist of fields |
| CVE-2026-97029 | A sandboxed app could send signals to a process group containing a parent process outside its sandbox |
The first two are the serious ones. System-wide Flatpak installs go through a privileged helper, and the bugs let a malicious package abuse that helper to damage files it should never touch. The attack requires you to install the malicious app, so the risk is mostly from third-party remotes rather than Flathub, but “install one bad app and lose system files” is exactly what a sandbox is meant to prevent.
The bundled xdg-dbus-proxy fallback also moves to 0.1.9, fixing CVE-2026-93676 and CVE-2026-94422, and symlink traversal protections were tightened across the board.
1.18.3 came first
Flatpak 1.18.3 landed on September 22 with non-security fixes: flatpak-spawn subsandboxes failed to start when apps used --no-talk-name, bundle installs with explicit key bytes crashed, and 1.18.2 had broken some app and runtime builds, especially on SELinux systems. It also updated the bundled Bubblewrap to 0.12.0 (fixing CVE-2026-87766) and xdg-dbus-proxy to 0.1.8.
What to do
Update through your distribution as soon as 1.18.4 appears:
flatpak --version # want 1.18.4 or a distro backport
sudo apt upgrade flatpak # Debian / Ubuntu
sudo dnf upgrade flatpak # Fedora
Distribution packages may keep the version number and backport the fixes, so check your distro’s security tracker if the version looks older.
While you are at it, flatpak remotes lists every remote you trust. Every remote can ship code that runs through Flatpak’s privileged install path, so remove any you no longer use. Our Flatpak permissions guide covers the sandbox side, and Snap vs Flatpak vs AppImage compares how each format handles trust.