Flatpak 1.18.1 and 1.19.0 Pre-release Fix 10 Critical CVEs and Add Polkit Downgrade Support

Published by

Flatpak has released version 1.18.1, which addresses ten critical CVEs related to security vulnerabilities, including full sandbox escapes and privilege escalation, making immediate upgrades essential for users running untrusted applications. Alongside this stable patch, a pre-release version 1.19.0 introduces new features such as Polkit-authenticated system-wide downgrades and a coredump listing command for debugging purposes. The vulnerabilities fixed in version 1.18.1 include symlink attacks and an anti-downgrade policy bypass that could allow unprivileged users to roll back system apps. Users are advised to apply the 1.18.1 patch immediately while testing the 1.19.0 pre-release in isolated environments before deploying it in production settings



Flatpak 1.18.1 and 1.19.0 Pre-release Fix 10 Critical CVEs and Add Polkit Downgrade Support

Flatpak released version 1.18.1, a critical security patch addressing ten CVEs that include full sandbox escapes and arbitrary root privilege escalation. The update closes vulnerabilities ranging from symlink attacks on app data directories to an anti-downgrade policy bypass, making an immediate upgrade essential for anyone running OCI images or untrusted apps. Bundled alongside the stability fix, the 1.19.0 pre-release introduces Polkit-authenticated system-wide downgrades, a new coredump listing command for debugging, and a bytes-per-second progress API for UI development. While the 1.18.1 build should be applied across all distributions immediately, developers should test the 1.19.0 candidate in isolated environments before adopting it for production workloads.

Flatpak 1.18.1 and 1.19.0 Pre-release Fix 10 Critical CVEs and Add Polkit Downgrade Support @ Linux Compatible