In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "flatpak",
"binary_version": "0.10.3-1"
},
{
"binary_name": "flatpak-dbgsym",
"binary_version": "0.10.3-1"
},
{
"binary_name": "flatpak-tests",
"binary_version": "0.10.3-1"
},
{
"binary_name": "flatpak-tests-dbgsym",
"binary_version": "0.10.3-1"
},
{
"binary_name": "gir1.2-flatpak-1.0",
"binary_version": "0.10.3-1"
},
{
"binary_name": "libflatpak-dev",
"binary_version": "0.10.3-1"
},
{
"binary_name": "libflatpak-doc",
"binary_version": "0.10.3-1"
},
{
"binary_name": "libflatpak0",
"binary_version": "0.10.3-1"
},
{
"binary_name": "libflatpak0-dbgsym",
"binary_version": "0.10.3-1"
}
]
}