CVE-2026-97025: Flatpak: flatpak: world-readable oci authentication token in system-helper cache path
Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate the authenticated user against the OCI repository. Only OCI-based sources (e.g. as used by Fedora) are affected; libostree-based sources such as Flathub are not.
Other sources
GHSA-7rvf-rqr3-43j4 (https://github.com/flatpak/flatpak/security/advisories/GHSA-7rvf-rqr3-43j4)
Description: When downloading apps or runtimes from an OCI repository that requires authentication, the OCI authentication token is written with the default permissions 0644. On multi-user systems this allows other local users to read the token file. This is related to GHSA-r9w3-qx54-qvc8 but with a different impact: unlike that issue, this one is not mitigated by a restrictive umask. libostree repositories such as Flathub are not affected; this only applies to apps, runtimes, or extensions downloaded from an OCI repository (such as those used by Fedora).
Mitigation: No known mitigation other than updating, or using libostree repositories (e.g. Flathub) or unauthenticated/public OCI repositories instead. Patched in 1.18.4 by commit f911bbf0 ("oci: Stop persisting bearer token to child repo on disk"). Credit: Found by AISLE in cooperation with Red Hat.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Flatpakto a version that resolves this vulnerability.Fixed in 1.18.4 - Compensating control
Use libostree repositories such as Flathub instead of OCI-based repositories for apps, runtimes, or extensions.
Event History
Frequently Asked Questions
Which deployments are exposed?
Exposure requires a multi-user system that downloads apps, runtimes, or extensions from an OCI repository requiring authentication. libostree repositories, including Flathub, are not affected; public or otherwise unauthenticated OCI repositories do not expose an authentication token.
What does an attacker need to exploit this?
An attacker needs local access as another user on the same multi-user system and must be able to read the world-readable token file in the system-helper cache directory. The disclosed token can then be used to impersonate the authenticated user to the OCI repository.
Does a restrictive umask prevent the issue?
No. Unlike the related issue GHSA-r9w3-qx54-qvc8, this issue is not mitigated by a restrictive umask.
What can be done if an update cannot be applied immediately?
There is no known mitigation other than updating. Temporary alternatives are to use libostree repositories such as Flathub, or OCI repositories that do not require authentication.