https://seclists.org/oss-sec/2026/q2/93: xdg-desktop-portal GHSA-rqr9-jwwf-wxgj: Trashing of arbitrary host files
Published Apr 10, 2026
·Updated
Affected Software
1 affected component
Flatpak xdg-desktop-portal<1.20.4, <1.21.1
Frequently Asked Questions
1
What is the severity of GHSA-rqr9-jwwf-wxgj?
The severity of GHSA-rqr9-jwwf-wxgj is considered less serious compared to similar vulnerabilities.
2
How do I fix GHSA-rqr9-jwwf-wxgj?
To fix GHSA-rqr9-jwwf-wxgj, ensure that you update to the latest version of xdg-desktop-portal.
3
What systems are affected by GHSA-rqr9-jwwf-wxgj?
GHSA-rqr9-jwwf-wxgj affects systems using the Flatpak version of xdg-desktop-portal.
4
What is the exploit potential of GHSA-rqr9-jwwf-wxgj?
The exploit potential of GHSA-rqr9-jwwf-wxgj lies in the ability of a malicious Flatpak app to delete arbitrary host files.
5
Who reported GHSA-rqr9-jwwf-wxgj?
GHSA-rqr9-jwwf-wxgj was reported by Codean Labs.