Description
A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host during the build process, resulting in arbitrary code execution with the privileges of the user running flatpak-builder.
Published: 2026-09-17
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Avoid using use-git-am: true when processing untrusted manifests or source material. Where untrusted builds are required, perform builds inside disposable virtual machines or other isolated environments.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9

Thu, 17 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host during the build process, resulting in arbitrary code execution with the privileges of the user running flatpak-builder.
Title Flatpak-builder: host code execution via `git am` hook execution in patch source extraction (`use-git-am`)
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-94
CPEs cpe:/o:redhat:enterprise_linux:10
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-17T08:26:31.448Z

Reserved: 2026-09-07T05:35:25.012Z

Link: CVE-2026-86320

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T08:17:02.200

Modified: 2026-09-17T09:16:42.473

Link: CVE-2026-86320

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')