Junglewise Threat Intelligence

CVE-2026-74859: GNOME Tweaks path traversal in shell theme installer

CVE-2026-74859 · Severity: medium · CVSS 6.8 · Published 2026-09-08

Vendors: Gnome.

Executive brief

GNOME Tweaks is a configuration utility used to customize GNOME desktop environments. The shell theme installer feature fails to validate file paths when extracting theme archives, allowing a crafted ZIP file to write files outside the intended themes directory. An attacker could use this to overwrite system files or plant malicious code if a user installs a malicious theme.

Technical details

The vulnerability is a path traversal flaw (CWE-22) in the shell theme installer component of gnome-tweaks. When extracting user-supplied ZIP archives, the application does not validate or sanitize archive member paths, allowing an attacker to use directory traversal sequences (../, absolute paths, or symlink entries) to write files outside ~/.themes. The attack requires local access and user interaction—specifically, a user must actively choose to install a crafted theme via the gnome-tweaks GUI. Successful exploitation can result in unauthorized file modification or creation, potentially leading to code execution if critical system or user files are overwritten. A patch validating archive paths before extraction is required to remediate this issue.

Affected products

  • GNOME Tweaks <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References