[Pkg-utopia-maintainers] Bug#1147700: CVE-2026-86320: Arbitrary host code execution via git hooks during module source extraction
Simon McVittie
smcv at debian.org
Mon Sep 14 13:40:50 BST 2026
Control: tags -1 + pending
On Mon, 14 Sep 2026 at 13:36:25 +0100, Simon McVittie wrote:
>https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-j5p8-jgjc-f3xv
>If flatpak-builder is run against an untrusted manifest and the manifest
>specifies `use-git-am: true`, a malicious module source can trigger
>arbitrary code execution on the host system by adding a
>`post-applypatch` hook.
I'll try to upload 1.4.11 soon to fix this in unstable (although I'd be
grateful if someone who uses flatpak-builder more regularly than I do
can take responsibility).
smcv
More information about the Pkg-utopia-maintainers
mailing list