
CVE-2026-40354 Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash. https://www.cve.org/CVERecord?id=CVE-2026-40354
Post summary
The tweet announces CVE‑2026‑40354, stating that Flatpak xdg‑desktop‑portal versions before 1.20.4 and 1.21.x before 1.21.1 allow any Flatpak app to trash host files via a symlink attack on g_file_trash. No PoC, exploit, active usage, patch, or false‑positive claim is presented.
