yocto ▾
›
master ▾
›
vulnerability
›
CVE-2026-40354
Component Overview
Vulnerability Overview
Name
CVE-2026-40354
Source
NVD (
link
)
Debian (
link
)
Description
Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash.
CWEs
CWE-61
Published Date
Apr 11, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/flatpak/xdg-desktop-portal/releases/tag/1.20.4
Product
https://github.com/flatpak/xdg-desktop-portal/releases/tag/1.21.1
Product
https://github.com/flatpak/xdg-desktop-portal/security/advisories/GHSA-rqr9-jwwf-wxgj
Vendor Advisory
https://www.openwall.com/lists/oss-security/2026/04/10/14
Mailing List
Analysis
#
Affected Component
Analysis
xdg-desktop-portal
Not Affected
Vulnerability Ratings
#
2.9
CVSSv31
6.3
CVSSv31
NaN
other
Others affected component
#
Name
Project
Project Version
Version
Status
xdg-desktop-portal
yocto
scarthgap
1.18.4
Exploitable