Package: flatpak-builder Version: 1.4.10-1 Severity: grave Tags: security help Justification: user security hole X-Debbugs-Cc: Debian Security Team <[email protected]>
https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-j5p8-jgjc-f3xv If flatpak-builder is run against an untrusted manifest and the manifest specifies `use-git-am: true`, a malicious module source can trigger arbitrary code execution on the host system by adding a `post-applypatch` hook. I'm erring on the side of caution and reporting this as grave, but it can maybe be downgraded to important since most people only build Flatpak apps whose manifest they have written (or at least, had the opportunity to audit) themselves. It's mainly a serious problem for repository-as-a-service providers that accept untrusted apps for building, like Flathub. If this needs fixing in trixie, either with a DSA or in a point release, I'd appreciate help. (Felix, would you be able to take this one?) smcv

