Skip to content
flatpak 1.14.6

Security fixes:

 * Don't allow an executable name to be misinterpreted as a command-line
   option for bwrap(1). This prevents a sandbox escape where a malicious
   or compromised app could ask xdg-desktop-portal to generate a .desktop
   file with access to files outside the sandbox. (CVE-2024-32462)

Other bug fixes:

 * Don't parse `<developer><name/></developer>` as the application name
   (#5700)

Git-EVTag-v0-SHA512: 1c64befa19c599f921421f6b07cda67c612635ff7213a4ddd9bb3e155abc82f05ce351f56c7ecb895781ce5351e136b3e8e6e7837077d7027f43269fed5e9a38