Logo
vulnerabilityCVE-2026-40354
Name
CVE-2026-40354
Source
NVD ( link)Debian ( link)
Description
Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
xdg-desktop-portal
Not Affected

Vulnerability Ratings#


2.9
CVSSv31
6.3
CVSSv31
NaN
other

Others affected component#


Name
Project
Project Version
Version
Status
yocto
scarthgap
1.18.4
Exploitable