Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash.
| Vendor | Product | Versions |
|---|---|---|
| flatpak | xdg-desktop-portal | 0, 1.21.0 |
Updated severity to CRITICAL and noted that no exploit is available.
Initial creation