Executive brief
GNOME Tweaks is a configuration utility used to customize GNOME desktop environments. The shell theme installer feature fails to validate file paths when extracting theme archives, allowing a crafted ZIP file to write files outside the intended themes directory. An attacker could use this to overwrite system files or plant malicious code if a user installs a malicious theme.
Technical details
The vulnerability is a path traversal flaw (CWE-22) in the shell theme installer component of gnome-tweaks. When extracting user-supplied ZIP archives, the application does not validate or sanitize archive member paths, allowing an attacker to use directory traversal sequences (../, absolute paths, or symlink entries) to write files outside ~/.themes. The attack requires local access and user interaction—specifically, a user must actively choose to install a crafted theme via the gnome-tweaks GUI. Successful exploitation can result in unauthorized file modification or creation, potentially leading to code execution if critical system or user files are overwritten. A patch validating archive paths before extraction is required to remediate this issue.
Affected products
- GNOME Tweaks <UNKNOWN>
Timeline
- 2026-09-08: disclosed