
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-97025 is a credential/token disclosure vulnerability in Flatpak where OCI repository authentication tokens are written with world-readable permissions (0644) in the system-helper's cache directory. This allows any local user on a multi-user system to read the token and impersonate the authenticated user against the OCI repository. Only OCI-based sources (e.g., as used by Fedora) are affected; libostree-based sources such as Flathub are not impacted. The vulnerability was disclosed on September 28, 2026, and carries a CVSS v3.1 base score of 3.2 (Low) (Red Hat CVE, GitHub Advisory).
The root cause is classified as CWE-378 (Creation of Temporary File With Insecure Permissions). When Flatpak downloads apps or runtimes from an authenticated OCI repository, it writes the bearer token to the system-helper's cache directory using the default file permissions of 0644, making it readable by all local users. Critically, this flaw is not mitigated by a restrictive umask, distinguishing it from the related issue GHSA-r9w3-qx54-qvc8. The fix, committed as f911bbf ("oci: Stop persisting bearer token to child repo on disk"), was included in Flatpak 1.18.4 (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows any local user on a multi-user system to read the OCI authentication token from the cache directory and use it to impersonate the authenticated user when accessing OCI repositories. The impact is limited to confidentiality — there is no integrity or availability impact. The scope is considered changed because the breach extends beyond the local system to the external OCI repository, potentially enabling unauthorized access to private container images or packages hosted there (Red Hat CVE, GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The vulnerability requires local access to the system and user interaction (a legitimate user must first authenticate with an OCI repository), limiting its practical exploitability. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Feedly, GitHub Advisory).
/var/cache/ or a similar system path) for the OCI bearer token file, which is written with 0644 permissions and is therefore readable by all local users.cat) to retrieve the bearer token from the cache file.Authorization: Bearer <token> headers to authenticate against the OCI repository and access private container images or packages as the victim user (GitHub Advisory, Red Hat Bugzilla).0644 in the Flatpak system-helper cache directory (e.g., under /var/cache/flatpak/ or similar); unexpected access timestamps on token cache files by users other than the owner./var/log/audit/audit.log) showing open or read syscalls on Flatpak OCI token cache files by users other than the file owner; authentication events against OCI registries from unexpected source IPs or user agents.registry.fedoraproject.org) bearing a valid Authorization: Bearer token originating from an unexpected user session or process (GitHub Advisory).The vulnerability is patched in Flatpak 1.18.4 via commit f911bbf ("oci: Stop persisting bearer token to child repo on disk"); upgrading to this version or later is the recommended remediation (GitHub Advisory, Red Hat Bugzilla). As a workaround where patching is not immediately possible, switch to libostree-based repositories such as Flathub, or use only unauthenticated (public) OCI repositories, as these are not affected by this issue. Additionally, administrators can review and restrict access controls on the system-helper cache directory to limit readability to privileged users only (Red Hat CVE).
The vulnerability was discovered by AISLE in cooperation with Red Hat and disclosed responsibly through GitHub's security advisory process. Community discussion appeared on platforms such as programming.dev and Privacy Guides forums following the release of Flatpak 1.18.4, which addressed six security vulnerabilities including this one. Coverage was also noted on Linux-focused outlets such as Linuxiac and LinuxCompatible, highlighting the release as a significant security update (Linuxiac, oss-sec).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."