flatpak: grant filesystem access to ~/.stackwallet
What changed, and why it matters
This change updates the Flatpak packaging for Stack Wallet so the app can read and write files in the user's ~/.stackwallet folder. This is likely needed so the wallet can store its data outside the sandbox. By itself, granting access to a dedicated wallet directory is a routine, expected permission change and not a vulnerability. However, it slightly widens the app's sandbox escape surface because a bug or malicious component inside the app could now access, modify, or delete files in that folder, including wallet backups or configuration data.
Review whether the permission can be narrowed (e.g., use --filesystem=~/.stackwallet:create or a portal-based file chooser) and ensure the directory contents are encrypted and access-controlled. Treat this as a packaging hardening review, not an urgent vulnerability patch.
Security signals we found
Flatpak sandbox permission broadened for a sensitive directory
No security-relevant description in commit title or message
No CVE, advisory, or researcher attribution present in commit
Evidence from the diff
The commit adds –filesystem=~/.stackwallet to the Flatpak finish-args in com.cypherstack.stackwallet.yaml. This exposes the host path ~/.stackwallet to the Flatpak sandbox. The change is minimal and appears functional (wallet data persistence). It does not introduce an obvious exploit, but it reduces sandbox isolation for a sensitive directory. There is no indication in the commit of a security fix, CVE, or reported vulnerability.
Changed components
flatpak/com.cypherstack.stackwallet.yamlInspect captured patch +1 / −0
diff --git a/flatpak/com.cypherstack.stackwallet.yaml b/flatpak/com.cypherstack.stackwallet.yaml
index 3707ccb..f8836e6 100644
--- a/flatpak/com.cypherstack.stackwallet.yaml
+++ b/flatpak/com.cypherstack.stackwallet.yaml
@@ -10,6 +10,7 @@ finish-args:
- --socket=fallback-x11
- --socket=wayland
- --device=dri
+ - --filesystem=~/.stackwallet
- --talk-name=org.freedesktop.secrets
- --talk-name=org.freedesktop.Notifications
Why this scored 29/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.