Executive brief
Bubblewrap is a sandboxing tool used to isolate applications and container images (including Flatpak packages) from the host system. A flaw in its sandbox initialization allows a local attacker to write files to arbitrary locations on the host filesystem by exploiting symlink traversal, bypassing the sandbox restrictions before the sandboxed process even starts. This could enable file creation or modification on the host system with the privileges of the user launching bubblewrap.
Technical details
The vulnerability is a symlink traversal flaw (CWE-59) in bubblewrap's sandbox setup phase. During the creation of files or directories under the new root, the code fails to properly resolve symlinks in parent paths, allowing them to escape via the /oldroot directory and write files outside the sandbox on the host filesystem. The attack occurs before the sandboxed process starts, requires local access with low privileges (non-root), and has no user interaction requirement. An attacker can exploit this by crafting untrusted application images (such as Flatpak packages) with symlink traversal payloads. The vulnerability is fixed in bubblewrap 0.12.0; older setuid builds have no upstream fix available.
Affected products
- Containers bubblewrap before 0.12.0
Timeline
- 2026-08-27: disclosed
- 2026-09-09: patched: Fixed in bubblewrap 0.12.0