This update for flatpak fixes the following issues:
- CVE-2026-34078: Arbitrary code execution via crafted symlinks in sandbox-expose options (bsc#1261769).
- CVE-2026-34079: Arbitrary file deletion on host via improper cache file path validation (bsc#1261770).