In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "0.10.3-1",
"binary_name": "flatpak"
},
{
"binary_version": "0.10.3-1",
"binary_name": "flatpak-dbgsym"
},
{
"binary_version": "0.10.3-1",
"binary_name": "flatpak-tests"
},
{
"binary_version": "0.10.3-1",
"binary_name": "flatpak-tests-dbgsym"
},
{
"binary_version": "0.10.3-1",
"binary_name": "gir1.2-flatpak-1.0"
},
{
"binary_version": "0.10.3-1",
"binary_name": "libflatpak-dev"
},
{
"binary_version": "0.10.3-1",
"binary_name": "libflatpak-doc"
},
{
"binary_version": "0.10.3-1",
"binary_name": "libflatpak0"
},
{
"binary_version": "0.10.3-1",
"binary_name": "libflatpak0-dbgsym"
}
]
}