[From nobody Tue Sep 15 01:09:32 2026
Received: (at submit) by bugs.debian.org; 14 Sep 2026 12:36:29 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-118.1 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 BODY_INCLUDES_PACKAGE,DKIMWL_WL_HIGH,DKIM_SIGNED,DKIM_VALID,
 DKIM_VALID_AU,DKIM_VALID_EF,FOURLA,FROMDEVELOPER,HAS_PACKAGE,
 SPF_HELO_NONE,SPF_PASS,USER_IN_DKIM_WELCOMELIST autolearn=ham
 autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 23; hammy, 150; neutral, 41; spammy,
 0. spammytokens:
 hammytokens:0.000-+--Hx-spam-relays-external:sk:stravin,
 0.000-+--H*RT:sk:stravin, 0.000-+--Hx-spam-relays-external:311,
 0.000-+--H*RT:311, 0.000-+--H*RT:108
Return-path: &lt;smcv@debian.org&gt;
Received: from stravinsky.debian.org ([2001:41b8:202:deb::311:108]:42938)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;smcv@debian.org&gt;) id 1x65vB-001fRq-2C
 for submit@bugs.debian.org; Mon, 14 Sep 2026 12:36:29 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; 
 s=smtpauto.stravinsky;
 h=X-Debian-User:Content-Type:MIME-Version:Message-ID:
 Subject:To:From:Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:
 Content-Description:In-Reply-To:References;
 bh=JrjnFLFYve1FHFM1sO1Fd50YtqxwAyCVs1AgBLF253g=; b=G5a6q83WsOHh5o2gQIfPyoTdTy
 2bQq7z6SEbalXyCROzN8wee2yx4elHZPdYiWDHq51AG/bTaOsKoN2ZiC4Ul5QR/zfS0U9wyvuNZ0w
 S8hbRQXaUsv3KIuP5PcNE87TSlv/QfWq2H3iorxoXyAkiEd03YAQqTAdZ5BjDNV1nw1qbfHdjFlnN
 GUh1zSsdjS6chIfIb9bP8fArRXypCc0Y1QJQz4UePCxF6EnQzZRfQA7q2PTsbcJYrh2Fp/gdetcDs
 VezIHwHLficIJJC2AxOJRo/Nkul2pjggpTVt0DWh3CALN7tVMnhyhEI1HNXqVq8gC9p5CSFZgfqCf
 YjuHbDcA==;
Received: from authenticated-user by stravinsky.debian.org with esmtpsa
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;smcv@debian.org&gt;) id 1x65vA-003cNL-0C
 for submit@bugs.debian.org; Mon, 14 Sep 2026 12:36:28 +0000
Date: Mon, 14 Sep 2026 13:36:25 +0100
From: Simon McVittie &lt;smcv@debian.org&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: CVE-2026-86320: Arbitrary host code execution via git hooks during
 module source extraction
Message-ID: &lt;aqfqSVnbqyTGSc46@definition.pseudorandom.co.uk&gt;
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
X-Mutt-Fcc: =.lists.debian/
X-Reportbug-Version: 13.2.0+nmu1
X-Debian-User: smcv
Delivered-To: submit@bugs.debian.org

Package: flatpak-builder
Version: 1.4.10-1
Severity: grave
Tags: security help
Justification: user security hole
X-Debbugs-Cc: Debian Security Team &lt;team@security.debian.org&gt;

https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-j5p8-jgjc-f3xv

If flatpak-builder is run against an untrusted manifest and the manifest 
specifies `use-git-am: true`, a malicious module source can trigger 
arbitrary code execution on the host system by adding a 
`post-applypatch` hook.

I'm erring on the side of caution and reporting this as grave, but it 
can maybe be downgraded to important since most people only build 
Flatpak apps whose manifest they have written (or at least, had the 
opportunity to audit) themselves. It's mainly a serious problem for 
repository-as-a-service providers that accept untrusted apps for 
building, like Flathub.

If this needs fixing in trixie, either with a DSA or in a point release, 
I'd appreciate help. (Felix, would you be able to take this one?)

    smcv
]