[From nobody Tue Sep 15 01:09:31 2026
Received: (at submit) by bugs.debian.org; 14 Sep 2026 12:39:14 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-118.1 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 BODY_INCLUDES_PACKAGE,DKIMWL_WL_HIGH,DKIM_SIGNED,DKIM_VALID,
 DKIM_VALID_AU,DKIM_VALID_EF,FOURLA,FROMDEVELOPER,HAS_PACKAGE,
 SPF_HELO_NONE,SPF_PASS,USER_IN_DKIM_WELCOMELIST autolearn=ham
 autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 22; hammy, 150; neutral, 91; spammy,
 0. spammytokens:
 hammytokens:0.000-+--Hx-spam-relays-external:sk:stravin,
 0.000-+--H*RT:sk:stravin, 0.000-+--Hx-spam-relays-external:311,
 0.000-+--H*RT:311, 0.000-+--H*RT:108
Return-path: &lt;smcv@debian.org&gt;
Received: from stravinsky.debian.org ([2001:41b8:202:deb::311:108]:57210)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;smcv@debian.org&gt;) id 1x65xq-001gCI-2I
 for submit@bugs.debian.org; Mon, 14 Sep 2026 12:39:14 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; 
 s=smtpauto.stravinsky;
 h=X-Debian-User:Content-Type:MIME-Version:Message-ID:
 Subject:To:From:Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:
 Content-Description:In-Reply-To:References;
 bh=2XqwwgJXeCl5DTF+dIXnKN+8MX1EFoX40SsngMjroso=; b=Tu0fctINWITYCDgiQuI6l7eUrA
 qNd4/cBOgnhlDZviLYWtUyS8wEWFKidjQsg6KlSu/cpZtyLMF+wi7xu4FVqwsj/WkJMobni9tOfTo
 xgFV6I+PkHTXmjKkKGzxUzk8YZ3JbJHQW9vbSgU1B+GKhKXEJc1XWNU+pT+NavfXtC4d2Rx65UQip
 tBUt472eMSCwIu6lj1V9bCUEyeNCXfOQg+beqBGlOxud4PyhS3xB/YUtiWvtxuNC00c03xoRpNC9+
 vpyiCL3twZHgq6qPw9F5oOFI+59eUeVawILgos7NqYcRwTkuP+7rXzgfuxPQaHWCV41VeHwB7UOZR
 +xEw12gA==;
Received: from authenticated-user by stravinsky.debian.org with esmtpsa
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;smcv@debian.org&gt;) id 1x65xp-003cVP-0i
 for submit@bugs.debian.org; Mon, 14 Sep 2026 12:39:13 +0000
Date: Mon, 14 Sep 2026 13:39:11 +0100
From: Simon McVittie &lt;smcv@debian.org&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: flatpak-builder: GHSA-484h-v688-jq5j: Source URL scheme bypasses
 sandboxed mode protections across multiple source subtypes
Message-ID: &lt;aqfq7y62eOXIsHcO@definition.pseudorandom.co.uk&gt;
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
X-Debian-User: smcv
Delivered-To: submit@bugs.debian.org

Package: flatpak-builder
Version: 1.4.10-1
Severity: important
Tags: security help pending
X-Debbugs-Cc: Debian Security Team &lt;team@security.debian.org&gt;

https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-484h-v688-jq5j
&gt;In --sandbox mode, flatpak-builder is supposed to prevent
&gt;manifests from referencing sources outside the manifest directory.
&gt;This protection was only enforced for the dir source subtype
&gt;and file source subtype using a local path.
&gt;
&gt;It did not cover:
&gt;
&gt;  * url: values using the file:// scheme
&gt;  * archive, git, bzr, and svn source subtypes, which lacked
&gt;    sandboxed-mode confinement checks entirely
&gt;  * mirror-urls
&gt;
&gt;As a result, a manifest could use a file:// URI or a plain local
&gt;path to read or reference arbitrary files on the host filesystem
&gt;from within a sandboxed build, defeating the intended
&gt;containment.
&gt;
&gt;This is primarily relevant to systems building untrusted manifests.
&gt;
&gt;The exploitation is constrained under most cases due to either
&gt;requiring an exact checksum match, or previous access to the host
&gt;filesystem or external tools refusing to operate on file:// URI schemes
&gt;by default. Furthermore, sandboxed mode is not the default
&gt;mode of operation of flatpak-builder.

There is no CVE for this, and upstream was unsure whether it's 
CVE-worthy. Like CVE-2026-86320, it's primarily interesting for 
repository-as-a-service providers that build untrusted or semi-trusted 
source code, like Flathub.

I'll try to upload 1.4.11 to fix this and CVE-2026-86320 in unstable soon.

If this needs fixing in trixie, either with a DSA or in a point release, 
I'd appreciate help. (Felix, would you be able to take this one?)

    smcv
]