flatpak: grant filesystem access to ~/.stackwallet
What changed, and why it matters
This commit changes the Flatpak packaging for Stack Wallet so the app can read and write files in a folder named .stackwallet inside the user's home directory. Flatpak apps normally run in a sandbox with limited access to the rest of the system. The change gives the app access to one specific, named folder, which is a common and usually reasonable way for a wallet app to store its data. By itself, this is not a vulnerability, but it slightly widens the sandbox. If the app were ever compromised, that folder could be read or modified by the attacker.
Treat this as a routine packaging change. Review whether ~/.stackwallet access is the narrowest path needed, consider using --persist=.stackwallet instead if the data does not need to be visible outside the sandbox, and ensure the directory is created with restrictive permissions. No urgent security patch is indicated by this commit alone.
Security signals we found
Flatpak sandbox permission expanded from default to include a host filesystem path
No code-level bug or unsafe API use visible in the diff
No vendor statement of security relevance, CVE, or researcher attribution present
Evidence from the diff
The commit adds the Flatpak finish-arg –filesystem=~/.stackwallet to flatpak/com.cypherstack.stackwallet.yaml. This grants the sandboxed application persistent read/write access to $HOME/.stackwallet. The change is a one-line sandbox permission expansion. It does not introduce code-level flaws, but it reduces isolation between the app and the user’s home directory. The diff shows no other changes and no references to a security advisory or CVE.
Changed components
flatpak/com.cypherstack.stackwallet.yamlFlatpak sandbox permissions for Stack WalletInspect captured patch +1 / −0
diff --git a/flatpak/com.cypherstack.stackwallet.yaml b/flatpak/com.cypherstack.stackwallet.yaml
index 3707ccb..f8836e6 100644
--- a/flatpak/com.cypherstack.stackwallet.yaml
+++ b/flatpak/com.cypherstack.stackwallet.yaml
@@ -10,6 +10,7 @@ finish-args:
- --socket=fallback-x11
- --socket=wayland
- --device=dri
+ - --filesystem=~/.stackwallet
- --talk-name=org.freedesktop.secrets
- --talk-name=org.freedesktop.Notifications
Why this scored 26/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.