Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash.
CVSS Details
- CVSS 3.1 Base Score: 2.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade xdg-desktop-portal-debuginfoUpgrade xdg-desktop-portal-develUpgrade xdg-desktop-portal | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade xdg-desktop-portal-debuginfoUpgrade xdg-desktop-portal-develUpgrade xdg-desktop-portal-debugsourceUpgrade xdg-desktop-portal | May 19, 2026 | Apr 11, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Apr 11, 2026 |
| Ubuntu | — | Upgrade xdg-desktop-portal-devUpgrade xdg-desktop-portal | May 25, 2026 | May 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub