Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Avoid using use-git-am: true when processing untrusted manifests or source material. Where untrusted builds are required, perform builds inside disposable virtual machines or other isolated environments.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 17 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
Thu, 17 Sep 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host during the build process, resulting in arbitrary code execution with the privileges of the user running flatpak-builder. | |
| Title | Flatpak-builder: host code execution via `git am` hook execution in patch source extraction (`use-git-am`) | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 | |
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-17T08:26:31.448Z
Reserved: 2026-09-07T05:35:25.012Z
Link: CVE-2026-86320
No data.
Status : Received
Published: 2026-09-17T08:17:02.200
Modified: 2026-09-17T09:16:42.473
Link: CVE-2026-86320
No data.
OpenCVE Enrichment
No data.