CVE-2026-86320

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host during the build process, resulting in arbitrary code execution with the privileges of the user running flatpak-builder.
Configurations

No configuration.

History

17 Sep 2026, 16:18

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=2471023 - () https://bugzilla.redhat.com/show_bug.cgi?id=2471023 -
References () https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-j5p8-jgjc-f3xv - () https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-j5p8-jgjc-f3xv -

17 Sep 2026, 08:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-17 08:17

Updated : 2026-09-17 16:18


NVD link : CVE-2026-86320

Mitre link : CVE-2026-86320

CVE.ORG link : CVE-2026-86320


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')