/flatpak/proton-mail/
Proton Mail
Encrypted email and calendar
![]()
Proton Mail desktop for Mail and Calendar. This Flatpak wraps the official Linux RPM with zypak. It is not a vendor-official Flatpak and not the community Flathub wrapper.
Proton Mail is proprietary freeware; this Flatpak is a redistribution of the official RPM, not vendor official.

Install
flatpak --user remote-add --if-not-exists thepeoples \
https://flatpak.thepeoples.io/thepeoples.flatpakrepo
flatpak --user install -y thepeoples io.thepeoples.ProtonMail
flatpak --user install -y thepeoples io.thepeoples.ProtonMail//1.13.4Optional system install uses sudo flatpak remote-add --if-not-exists --system and sudo flatpak install -y --system. The //version form pins the advertised ostree branch; stable tracks the latest advertised tree.
Verify
- App id
io.thepeoples.ProtonMail, vendor Proton AG, version1.13.4, license proprietary - Download 115.8 MB · installed 304.5 MB
- sha256
3a6d2cbee27e728d0ad5c7c367318178d6425e3002929832ed0a4b62ed709cae - sha512
2db3d08fc0d1a0d1111c156900534150e414d4fb273d8dd82aa580b64d6f5ff97c620e53b94c70e270a230020132f40fc2d5f2b01786274c37c0a123f3b2f169(official source, checked after download fromhttps://proton.me/download/mail/linux/version.json) - Ostree key fingerprint
98D786877B6C4E8C6889CBD2E75B1C5B0CB2D841 - Homepage https://proton.me/mail
Input scan
Pinned rpm ProtonMail-desktop-1.13.4.rpm, extracted without install scripts, scanned before wrap. 2026-09-02 14:15 UTC · trivy 0.73.0 · vuln DB 2026-09-01.
Wrap
Layers this remote adds. Gate fails on CRITICAL.
none
gate pass
Vendor
In the upstream package. Not patched here.
1 HIGH · 1 MEDIUM
Vendor findings 2 · 1 HIGH · 1 MEDIUM
| Severity | ID | Package | Installed | Fixed | Title |
|---|---|---|---|---|---|
| HIGH | CVE-2026-70608 | electron | 40.10.1 | 42.0.1, 41.10.3, 39.8.10 | Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path |
| MEDIUM | CVE-2026-70606 | electron | 40.10.1 | 43.0.0, 42.5.1, 41.9.1, 40.10.6 | Electron: ProtocolResponse.url reuses the default session cache instead of the registering session |
Previous scans
Daily Trivy refresh. Current report plus the last 14 full scans; older copies are deleted.
| Scanned | Vuln DB | Version | Wrap | Vendor | Report |
|---|---|---|---|---|---|
| 2026-09-02 14:02 UTC | 2026-09-01 | 1.13.4 | none | 1 HIGH · 1 MEDIUM | JSON |
| 2026-09-02 06:50 UTC | 2026-09-01 | 1.13.4 | none | 1 HIGH · 1 MEDIUM | JSON |
| 2026-09-02 04:58 UTC | 2026-09-01 | 1.13.4 | none | 1 HIGH · 1 MEDIUM | JSON |
| 2026-09-02 04:31 UTC | 2026-09-01 | 1.13.4 | none | 1 HIGH · 1 MEDIUM | JSON |
| 2026-09-02 03:56 UTC | 2026-09-01 | 1.13.4 | none | 1 HIGH · 1 MEDIUM | JSON |
| 2026-09-02 03:44 UTC | 2026-09-01 | 1.13.4 | none | 1 HIGH · 1 MEDIUM | JSON |
| 2026-09-02 01:42 UTC | 2026-09-01 | 1.13.4 | none | 1 HIGH · 1 MEDIUM | JSON |
| 2026-09-01 07:28 UTC | 2026-09-01 | 1.13.4 | none | 1 HIGH · 1 MEDIUM | JSON |
| 2026-09-01 06:51 UTC | 2026-09-01 | 1.13.4 | none | 1 HIGH · 1 MEDIUM | JSON |
| 2026-08-31 09:27 UTC | 2026-08-31 | 1.13.4 | none | 1 HIGH · 1 MEDIUM | JSON |
| 2026-08-31 07:28 UTC | 2026-08-31 | 1.13.4 | none | 1 HIGH · 1 MEDIUM | JSON |
| 2026-08-31 06:50 UTC | 2026-08-31 | 1.13.4 | none | 1 HIGH · 1 MEDIUM | JSON |
| 2026-08-30 07:28 UTC | 2026-08-30 | 1.13.4 | none | 1 HIGH · 1 MEDIUM | JSON |
| 2026-08-30 06:51 UTC | 2026-08-30 | 1.13.4 | none | 1 HIGH · 1 MEDIUM | JSON |