Flatpak 1.18.4 Ships as Security-Focused Patch Release, Fixes Six Privilege-Escalation Vulnerabilities
Flatpak's newest point release closes six bugs, two of which let a malicious app delete or empty host files as root during an upgrade.
Flatpak released version 1.18.4 today, a patch that the project is treating as a priority. It closes six distinct vulnerabilities, and two of them let an attacker with a maliciously installed app read or destroy arbitrary files on your machine as root.
If you install apps system-wide or from publishers you don't fully trust, this one wants your attention soon.
Why These Bugs Actually Matter
Here's the part that makes 1.18.4 worth more than a typical point release. Most of these six bugs don't fire when you run an app. They fire when you install or upgrade one, and several need the privileged root context of the system helper.
That shifts the threat model. Instead of a bug you hit by opening a dodgy file, you're looking at something that triggers when you update software you already agreed to run. Install a compromised Flatpak and the attacker gets a foothold that reaches past the sandbox.
The two headline bugs are path-traversal tricks that empty or delete host files during an upgrade:
File overwrite via a resolv.conf symlink (CVE-2026-97024) which is CVSS 7.1, rated High. A malicious app could get host files like /etc/passwd, group, or machine-id emptied when it upgraded. The advisory is careful to note this is "not believed to be possible to replace these files with attacker-chosen content." Still, emptying /etc/passwd is data loss and a locked-out system. A sibling vector swaps in a resolv.conf symlink pointing at a file unlikely to exist. Reported by Sebastian Wick.
File deletion via path traversal (CVE-2026-97023) which is also CVSS 7.1, High. An attacker-chosen host file gets deleted during upgrade, again as root under system-wide install. Same reporter. The fix for this one overlaps heavily with the resolv.conf fix, both leaning on fd-relative operations for deploy-directory access.
The other four round out the list:
An OCI auth token leaked to other local users (CVE-2026-97025), which could expose credentials for private repositories. Temporary repo directories under /var/tmp/flatpak-cache-* had loose permissions (CVE-2026-97026). Both came from AISLE in cooperation with Red Hat.
.desktop and D-Bus .service files weren't filtered against an allowlist (CVE-2026-97027), opening the door to denial-of-service and unwanted host-side behavior. Reported by Markus Göllnitz.
And apps could signal an out-of-sandbox process group (CVE-2026-97029), meaning a bad app could kill the desktop environment by signaling its parent. Reported by Guthrie Armstrong of Coalition, Inc.
Not all of them are dramatic. The missing .desktop field filtering is annoying rather than catastrophic. But together they describe a project whose install path has become a serious attack surface.
A Pattern, Not a One-Off
1.18.4 doesn't arrive on an empty calendar. It's the newest in a run of security-heavy patch releases, and the shape of this batch only makes sense against what came before.
Skip ahead about seven weeks to Flatpak 1.18.1, released August 11, 2026. That drop fixed nine distinct vulnerabilities at once, including a full sandbox escape that handed an attacker read/write access to the whole host filesystem, plus a local root escalation via revokefs symlink traversal and commit tampering. It read like a major release wearing a point-release costume.
That release was credited to a wide cast: Ee Yang, AISLE with Red Hat, Sebastian Wick, Yehia Ali Mohamed Ezzat, and BreachX Zero Day Labs. It's a useful reminder that Flatpak runs heavily on coordinated responsible-disclosure partnerships, Red Hat's security team in particular.
The in-between releases kept the rhythm going. 1.18.2 on August 27 chased down system-helper and portal crashes, plus a build failure against older GLib. Then 1.18.3 on September 22 updated bubblewrap and xdg-dbus-proxy, and fixed regressions from 1.18.2 that broke app builds, especially on SELinux systems or non-per-user runtimes.
So the story over the last few months is clear: a wave of independently discovered privilege-escalation bugs, mostly symlink and path-traversal variants, pushed the project into a sustained hardening cycle. These are the classic persistent bug class in anything that manipulates filesystem paths as root.
For the record, the broader 1.18 feature line itself started June 8, 2026 with things like AMD compute-interface DRI device support and faster fish-shell startup. Recent point releases have quietly stopped being about features and stopped being about much besides security and stability.
The price of that focus is worth mentioning. If you were waiting for a new feature patch, you'll probably be underwhelmed. But when half your recent updates are about not getting owned during an app upgrade, "security-focused" is the best possible headline.
What You Should Do
Flatpak recommends moving to 1.18.4 or later as soon as you can. How you actually do that depends on how Flatpak itself landed on your machine.
If it ships as a flatpak, run this:
flatpak update org.freedesktop.Flatpak
Otherwise it comes through your distro's normal package manager, which usually means waiting for the next point update. Distributions rolling a system-packaged Flatpak will typically fold these fixes in there.
One more thing worth doing: make sure your bundled bubblewrap and xdg-dbus-proxy are current. Both got security-relevant updates across the 1.18.x line, and both sit right at the heart of the sandbox model. xdg-dbus-proxy alone picked up 0.1.9 here, pulling upstream hardening tied to two separate CVEs.
The advisory's own workaround is about as low-effort as it gets: don't install Flatpak apps from publishers you don't trust, especially system-wide. The real fix is just updating. And for what it's worth, both workarounds point at the same underlying habit.
Reporter credits landed alongside the release on GitHub, posted by maintainer Simon McVittie (smcv). The fd-relative file operations used to close the path-traversal bugs aren't a band-aid so much as a structural rewrite of how the deploy directory gets accessed, which is the whole point.
The advisories came through GitHub Security Advisories, and the fixes are committed at a02d0ba. Keep an eye on the Flatpak NEWS changelog at the 1.18.4 tag if you want the raw diff, and head to flatpak.org for the full project history if you want to understand how a 2012 GUADEC planning session became the thing running your desktop apps.
Head here to the GibHub release page.
