Opened 6 months ago
Closed 6 months ago
#23127 closed enhancement (fixed)
xdg-desktop-portal-1.20.4
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (8)
comment:1 by , 6 months ago
| Summary: | xdg-desktop-portal--1.20.4 → xdg-desktop-portal-1.20.4 |
|---|
comment:2 by , 6 months ago
comment:3 by , 6 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:4 by , 6 months ago
Changes in 1.20.4 ================= Released: 2026-04-08 - Prevent trashing of arbitrary host files (GHSA-rqr9-jwwf-wxgj)
Fixed at b16a999475.
I'm going to leave this open for now. Right now it looks like this only affects flatpak.
comment:5 by , 6 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
comment:6 by , 6 months ago
| Owner: | changed from to |
|---|
comment:7 by , 6 months ago
| Priority: | normal → elevated |
|---|
In my interpretation it looks like this isn't specific to Flatpak apps, but rather anything that uses the Trash portal. This may include programs such as Nautilus or Dolphin
https://github.com/flatpak/xdg-desktop-portal/security/advisories/GHSA-rqr9-jwwf-wxgj rates it as Moderate but with no CVE (which is fair honestly, it would be close to a duplicate of the Flatpak-specific issue)
Note:
See TracTickets
for help on using tickets.

I heard it contains the change related to some flatpak vulnerability but I'm unsure if it counts as a priority=high.