[Pkg-utopia-maintainers] Bug#1147700: CVE-2026-86320: Arbitrary host code execution via git hooks during module source extraction

Simon McVittie smcv at debian.org
Mon Sep 14 13:40:50 BST 2026


Control: tags -1 + pending

On Mon, 14 Sep 2026 at 13:36:25 +0100, Simon McVittie wrote:
>https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-j5p8-jgjc-f3xv
>If flatpak-builder is run against an untrusted manifest and the manifest
>specifies `use-git-am: true`, a malicious module source can trigger
>arbitrary code execution on the host system by adding a
>`post-applypatch` hook.

I'll try to upload 1.4.11 soon to fix this in unstable (although I'd be 
grateful if someone who uses flatpak-builder more regularly than I do 
can take responsibility).

     smcv



More information about the Pkg-utopia-maintainers mailing list