CVE-2026-40354
EUVD-2026-2162511.04.2026, 01:16
Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| flatpak | xdg-desktop-portal | 𝑥 < 1.20.4 |
| flatpak | xdg-desktop-portal | 1.21.0 |
𝑥
= Vulnerable software versions
Debian Releases