xdg-desktop-portal works by exposing a series of D-Bus interfaces known as portals under a well-known name (org.freedesktop.portal.Desktop) and object path (/org/freedesktop/portal/desktop). The portal interfaces include APIs for file access, opening URIs, printing and others.
Security Fix(es):
Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on gfiletrash.(CVE-2026-40354)
{
"severity": "Low"
}{
"src": [
"xdg-desktop-portal-1.20.4-1.oe2403.src.rpm"
],
"aarch64": [
"xdg-desktop-portal-1.20.4-1.oe2403.aarch64.rpm",
"xdg-desktop-portal-debuginfo-1.20.4-1.oe2403.aarch64.rpm",
"xdg-desktop-portal-debugsource-1.20.4-1.oe2403.aarch64.rpm",
"xdg-desktop-portal-devel-1.20.4-1.oe2403.aarch64.rpm"
],
"x86_64": [
"xdg-desktop-portal-1.20.4-1.oe2403.x86_64.rpm",
"xdg-desktop-portal-debuginfo-1.20.4-1.oe2403.x86_64.rpm",
"xdg-desktop-portal-debugsource-1.20.4-1.oe2403.x86_64.rpm",
"xdg-desktop-portal-devel-1.20.4-1.oe2403.x86_64.rpm"
]
}