Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 27 Apr 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:flatpak:xdg-desktop-portal:*:*:*:*:*:*:*:* cpe:2.3:a:flatpak:xdg-desktop-portal:1.21.0:*:*:*:*:*:*:* |
Wed, 15 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | File Deletion via Symlink Attack in Flatpak XDG Desktop Portal | flatpak: xdg-desktop-portal: Flatpak xdg-desktop-portal: File deletion via symlink attack |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 13 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | File Deletion via Symlink Attack in Flatpak XDG Desktop Portal |
Mon, 13 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flatpak
Flatpak xdg-desktop-portal |
|
| Vendors & Products |
Flatpak
Flatpak xdg-desktop-portal |
Sat, 11 Apr 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash. | |
| Weaknesses | CWE-61 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-15T15:14:27.291Z
Reserved: 2026-04-11T00:29:02.889Z
Link: CVE-2026-40354
Updated: 2026-04-15T15:14:22.002Z
Status : Analyzed
Published: 2026-04-11T01:16:16.270
Modified: 2026-04-27T23:11:58.333
Link: CVE-2026-40354
OpenCVE Enrichment
Updated: 2026-04-14T16:36:16Z