CVE-2026-40354 - Flatpak xdg-desktop-portal Privilege Escalation Vulnerability
CVE ID :CVE-2026-40354
Published : April 11, 2026, 12:29 a.m. | 40 minutes ago
Description :Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : April 11, 2026, 12:29 a.m. | 40 minutes ago
Description :Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...