/flatpak/sparrow/

Sparrow

Bitcoin wallet with hardware-wallet support

Sparrow is a desktop Bitcoin wallet focused on privacy, hardware wallets, and full verification. This Flatpak wraps the vendor-signed Linux tarball.

Sparrow is Apache-2.0; this Flatpak is a redistribution, not vendor official.

bitcoinwallethardware walletpsbtelectrum

Send flow
Send flow
Wallet history
Wallet history

Install

flatpak --user remote-add --if-not-exists thepeoples \
  https://flatpak.thepeoples.io/thepeoples.flatpakrepo
flatpak --user install -y thepeoples io.thepeoples.Sparrow
flatpak --user install -y thepeoples io.thepeoples.Sparrow//2.5.4

Optional system install uses sudo flatpak remote-add --if-not-exists --system and sudo flatpak install -y --system. The //version form pins the advertised ostree branch; stable tracks the latest advertised tree.

Previous versions

The remote keeps the current tree plus the last two vendor versions as extra ostree branches for rollback. Objects stay on the remote after a branch is dropped (publish does not delete).

flatpak --user install -y thepeoples io.thepeoples.Sparrow//2.5.2

Hardware-wallet udev

The Flatpak cannot write host udev rules. After you install the app, run the helper that ships inside it. It vendor-verifies the same pinned tarball, rewrites rules to uaccess only, and installs them under /etc/udev/rules.d/. It does not add a plugdev group. It will ask for sudo.

sudo ~/.local/share/flatpak/app/io.thepeoples.Sparrow/current/active/files/bin/sparrow-udev

System install uses the same file under /var/lib/flatpak/app/io.thepeoples.Sparrow/current/active/files/bin/sparrow-udev. Read the script first at /flatpak/helpers/io.thepeoples.Sparrow.sh (sha256 f3c607a3905e334cb0498a250c70a75f7c7b320f12fdc8c9a068fed58f66dc03).

Verify

Input scan

Pinned tarball sparrowwallet-2.5.4-x86_64.tar.gz, extracted without install scripts, scanned before wrap. 2026-09-02 14:15 UTC · trivy 0.73.0 · vuln DB 2026-09-01.

Wrap

Layers this remote adds. Gate fails on CRITICAL.

none

gate pass

Vendor

In the upstream package. Not patched here.

4 HIGH · 9 MEDIUM · 3 LOW

Vendor findings 16 · 4 HIGH · 9 MEDIUM · 3 LOW
SeverityIDPackageInstalledFixedTitle
HIGHGHSA-r7wm-3cxj-wff9com.fasterxml.jackson.core:jackson-core2.21.12.18.8, 2.21.4jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGHCVE-2026-54512com.fasterxml.jackson.core:jackson-databind2.21.12.18.8, 3.1.4, 2.21.4jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGHCVE-2026-54513com.fasterxml.jackson.core:jackson-databind2.21.12.18.8, 2.21.4, 3.1.4jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGHCVE-2026-2332org.eclipse.jetty:jetty-http9.4.54.v2024020812.1.7, 12.0.33, 11.0.29, 10.0.28, 9.4.60org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
MEDIUMCVE-2026-54514com.fasterxml.jackson.core:jackson-databind2.21.12.18.8, 2.21.4, 3.1.4jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUMCVE-2026-54515com.fasterxml.jackson.core:jackson-databind2.21.13.1.4, 2.18.9, 2.21.5, 2.22.1jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUMCVE-2026-54516com.fasterxml.jackson.core:jackson-databind2.21.12.21.4, 3.1.4jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties
MEDIUMCVE-2026-54517com.fasterxml.jackson.core:jackson-databind2.21.12.21.4, 3.1.4jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application
MEDIUMCVE-2026-54518com.fasterxml.jackson.core:jackson-databind2.21.12.21.4jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass
MEDIUMCVE-2026-59888com.fasterxml.jackson.core:jackson-databind2.21.12.18.8, 2.21.4com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUMCVE-2026-59889com.fasterxml.jackson.core:jackson-databind2.21.12.21.5, 2.18.9, 2.22.1jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
MEDIUMGHSA-mhm7-754m-9p8wcom.fasterxml.jackson.core:jackson-databind2.21.12.18.9, 2.21.5jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
MEDIUMCVE-2024-6763org.eclipse.jetty:jetty-http9.4.54.v2024020812.0.12org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
LOWCVE-2026-10532ch.qos.logback:logback-core1.5.321.5.34Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ...
LOWCVE-2026-9828ch.qos.logback:logback-core1.5.321.5.33Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ...
LOWCVE-2025-11143org.eclipse.jetty:jetty-http9.4.54.v2024020812.0.31, 12.1.5org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing

Full report (JSON)

Previous scans

Daily Trivy refresh. Current report plus the last 14 full scans; older copies are deleted.

ScannedVuln DBVersionWrapVendorReport
2026-09-02 14:02 UTC2026-09-012.5.4none4 HIGH · 9 MEDIUM · 3 LOWJSON
2026-09-02 06:50 UTC2026-09-012.5.4none4 HIGH · 9 MEDIUM · 3 LOWJSON
2026-09-02 04:58 UTC2026-09-012.5.4none4 HIGH · 9 MEDIUM · 3 LOWJSON
2026-09-02 04:30 UTC2026-09-012.5.4none4 HIGH · 9 MEDIUM · 3 LOWJSON
2026-09-02 03:56 UTC2026-09-012.5.4none4 HIGH · 9 MEDIUM · 3 LOWJSON
2026-09-02 03:43 UTC2026-09-012.5.4none4 HIGH · 9 MEDIUM · 3 LOWJSON
2026-09-02 01:42 UTC2026-09-012.5.4none4 HIGH · 9 MEDIUM · 3 LOWJSON
2026-09-01 07:27 UTC2026-09-012.5.4none4 HIGH · 9 MEDIUM · 3 LOWJSON
2026-09-01 06:51 UTC2026-09-012.5.4none4 HIGH · 9 MEDIUM · 3 LOWJSON
2026-08-31 09:27 UTC2026-08-312.5.4none4 HIGH · 9 MEDIUM · 3 LOWJSON
2026-08-31 07:27 UTC2026-08-312.5.4none4 HIGH · 9 MEDIUM · 3 LOWJSON
2026-08-31 06:50 UTC2026-08-312.5.4none4 HIGH · 9 MEDIUM · 3 LOWJSON
2026-08-30 07:28 UTC2026-08-302.5.4none4 HIGH · 9 MEDIUM · 3 LOWJSON
2026-08-30 06:50 UTC2026-08-302.5.4none4 HIGH · 9 MEDIUM · 3 LOWJSON