CVE-2026-40354: Medium severity Flatpak xdg-desktop-portal vulnerability
Published Apr 11, 2026
·Updated
Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on gfiletrash.
Affected Software
4 affected componentsFixes available
Flatpak xdg-desktop-portal<1.20.4, >=1.21.0<1.21.1
Flatpak xdg-desktop-portal<1.20.4
Flatpak xdg-desktop-portal=1.21.0
debian/xdg-desktop-portal<=1.8.1-1, <=1.16.0-2, <=1.20.3+ds-1
1.20.4+ds-1
Event History
Apr 11, 2026
CVE Published
via MITRE·12:29 AM
Data Sourced
via MITRE·12:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeaknessAffected Software
May 21, 2026
Data Sourced
via Ubuntu·03:46 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·03:48 PM
DescriptionAffected Software
Data Sourced
via Launchpad·03:48 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-40354?
CVE-2026-40354 has a medium severity rating of 6.3.
2
How does CVE-2026-40354 impact Flatpak applications?
CVE-2026-40354 allows any Flatpak app to trash files in the host context through a symlink attack on g_file_trash.
3
How do I fix CVE-2026-40354?
To fix CVE-2026-40354, update to Flatpak xdg-desktop-portal version 1.20.4 or 1.21.1 or later.
4
When was CVE-2026-40354 published?
CVE-2026-40354 was published on April 11, 2026.
5
What versions of Flatpak xdg-desktop-portal are affected by CVE-2026-40354?
CVE-2026-40354 affects Flatpak xdg-desktop-portal versions before 1.20.4 and 1.21.x before 1.21.1.