/flatpak/t3-code/

T3 Code

Early desktop GUI for AI coding agents

alpha

T3 Code is a very early MIT Electron app. This Flatpak will wrap the official Linux AppImage. It is not a vendor-official Flatpak.

T3 Code is MIT; this Flatpak is a redistribution, not vendor official.

t3codeagentelectron

Agent session
Agent session

Install

flatpak --user remote-add --if-not-exists thepeoples \
  https://flatpak.thepeoples.io/thepeoples.flatpakrepo
flatpak --user install -y thepeoples io.thepeoples.T3Code
flatpak --user install -y thepeoples io.thepeoples.T3Code//0.0.37

Optional system install uses sudo flatpak remote-add --if-not-exists --system and sudo flatpak install -y --system. The //version form pins the advertised ostree branch; stable tracks the latest advertised tree.

Previous versions

The remote keeps the current tree plus the last two vendor versions as extra ostree branches for rollback. Objects stay on the remote after a branch is dropped (publish does not delete).

flatpak --user install -y thepeoples io.thepeoples.T3Code//0.0.33
flatpak --user install -y thepeoples io.thepeoples.T3Code//0.0.35

Verify

Input scan

Pinned appimage T3-Code-0.0.37-x86_64.AppImage, extracted without install scripts, scanned before wrap. 2026-09-02 14:16 UTC · trivy 0.73.0 · vuln DB 2026-09-01.

Wrap

Layers this remote adds. Gate fails on CRITICAL.

none

gate pass

Vendor

In the upstream package. Not patched here.

28 HIGH · 65 MEDIUM · 15 LOW

Vendor findings 108 · 28 HIGH · 65 MEDIUM · 15 LOW
SeverityIDPackageInstalledFixedTitle
HIGHCVE-2023-5217electron12.0.422.3.25, 24.8.5, 25.8.4, 26.2.4, 27.0.0-beta.8libvpx: Heap buffer overflow in vp8 encoding in libvpx
HIGHCVE-2026-34769electron12.0.438.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8Electron: Electron: Arbitrary code execution and security bypass via undocumented command-line switches
HIGHCVE-2026-34769electron39.2.638.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8Electron: Electron: Arbitrary code execution and security bypass via undocumented command-line switches
HIGHCVE-2026-34770electron12.0.438.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8Electron: Use-after-free in PowerMonitor on Windows and macOS
HIGHCVE-2026-34770electron39.2.638.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8Electron: Use-after-free in PowerMonitor on Windows and macOS
HIGHCVE-2026-34771electron12.0.438.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8electron: Electron: Memory corruption or application crash via use-after-free in permission request handling
HIGHCVE-2026-34771electron39.2.638.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8electron: Electron: Memory corruption or application crash via use-after-free in permission request handling
HIGHCVE-2026-34774electron12.0.439.8.1, 40.7.0, 41.0.0Electron: Electron: Memory corruption and crash due to use-after-free in offscreen rendering
HIGHCVE-2026-34774electron39.2.639.8.1, 40.7.0, 41.0.0Electron: Electron: Memory corruption and crash due to use-after-free in offscreen rendering
HIGHCVE-2026-34780electron39.2.639.8.0, 40.7.0, 41.0.0-beta.8electron: Electron: Context Isolation bypass via VideoFrame object transfer
HIGHCVE-2026-70601electron12.0.439.8.9, 40.9.2, 41.2.2, 42.0.0-beta.5Electron: Context isolation bypass via Function.prototype.bind hijack
HIGHCVE-2026-70601electron39.2.639.8.9, 40.9.2, 41.2.2, 42.0.0-beta.5Electron: Context isolation bypass via Function.prototype.bind hijack
HIGHCVE-2026-70601electron39.8.539.8.9, 40.9.2, 41.2.2, 42.0.0-beta.5Electron: Context isolation bypass via Function.prototype.bind hijack
HIGHCVE-2026-70604electron12.0.442.0.0, 41.4.0, 40.9.3, 39.8.10Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
HIGHCVE-2026-70604electron39.2.642.0.0, 41.4.0, 40.9.3, 39.8.10Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
HIGHCVE-2026-70604electron39.8.542.0.0, 41.4.0, 40.9.3, 39.8.10Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
HIGHCVE-2026-70608electron12.0.442.0.1, 41.10.3, 39.8.10Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
HIGHCVE-2026-70608electron39.2.642.0.1, 41.10.3, 39.8.10Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
HIGHCVE-2026-70608electron39.8.542.0.1, 41.10.3, 39.8.10Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
HIGHCVE-2026-13676fast-uri3.0.14.0.1, 3.1.3, 2.4.2fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization
HIGHCVE-2026-16221fast-uri3.0.12.4.3, 3.1.4, 4.1.1fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency
HIGHCVE-2026-18446fast-uri3.0.12.4.4, 3.1.5, 4.1.2fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority
HIGHCVE-2026-6321fast-uri3.0.13.1.1, 2.4.1fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies
HIGHCVE-2026-6322fast-uri3.0.13.1.2, 2.4.1fast-uri: fast-uri: URI authority bypass due to improper delimiter handling
HIGHCVE-2026-59869js-yaml4.1.03.15.0, 4.3.0js-yaml: js-yaml: Denial of Service via crafted YAML documents
HIGHGHSA-5p4m-2wfm-xmqjjs-yaml4.1.04.3.1, 3.15.1JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
HIGHCVE-2022-25883semver7.3.57.5.2, 6.3.1, 5.7.2nodejs-semver: Regular expression denial of service
HIGHCVE-2026-13697undici8.7.07.29.0, 8.9.0undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives
MEDIUMCVE-2025-69873ajv8.0.08.18.0, 6.14.0ajv: ReDoS via $data reference
MEDIUMCVE-2025-69873ajv8.6.38.18.0, 6.14.0ajv: ReDoS via $data reference
MEDIUMCVE-2021-39184electron12.0.411.5.0, 12.1.0, 13.3.0Electron's sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API
MEDIUMCVE-2022-29257electron12.0.415.5.0, 16.2.0, 17.2.0, 18.0.0-beta.6AutoUpdater module fails to validate certain nested components of the bundle
MEDIUMCVE-2022-36077electron12.0.418.3.7, 20.0.1, 19.0.11Electron: Redirection error and misuse of hashed credentials
MEDIUMCVE-2023-29198electron12.0.422.3.6, 23.2.3, 24.0.1, 25.0.0-alpha.2Electron context isolation bypass via nested unserializable return value
MEDIUMCVE-2023-39956electron12.0.422.3.19, 23.3.13, 24.7.1, 25.5.0, 26.0.0-beta.13Electron vulnerable to out-of-package code execution when launched with arbitrary cwd
MEDIUMCVE-2023-44402electron12.0.422.3.24, 24.8.3, 25.8.1, 26.2.1, 27.0.0-alpha.7ASAR Integrity bypass via filetype confusion in electron
MEDIUMCVE-2024-46993electron12.0.428.3.2, 29.3.3, 30.0.3Electron vulnerable to Heap Buffer Overflow in NativeImage
MEDIUMCVE-2025-55305electron12.0.435.7.5, 36.8.1, 37.3.1, 38.0.0-beta.6electron: ASAR Integrity Bypass via resource modification
MEDIUMCVE-2026-34765electron12.0.439.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5electron: Electron: Arbitrary code execution or information disclosure via incorrect window handling
MEDIUMCVE-2026-34765electron39.2.639.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5electron: Electron: Arbitrary code execution or information disclosure via incorrect window handling
MEDIUMCVE-2026-34767electron12.0.438.8.6, 39.8.3, 40.8.3, 41.0.3electron: Electron: HTTP Response Header Injection via attacker-controlled input
MEDIUMCVE-2026-34767electron39.2.638.8.6, 39.8.3, 40.8.3, 41.0.3electron: Electron: HTTP Response Header Injection via attacker-controlled input
MEDIUMCVE-2026-34772electron12.0.438.8.6, 39.8.0, 40.7.0, 41.0.0-beta.7Electron: Electron: Use-after-free vulnerability leads to memory corruption or crash
MEDIUMCVE-2026-34772electron39.2.638.8.6, 39.8.0, 40.7.0, 41.0.0-beta.7Electron: Electron: Use-after-free vulnerability leads to memory corruption or crash
MEDIUMCVE-2026-34773electron12.0.438.8.6, 39.8.1, 40.8.1, 41.0.0electron: Electron: Protocol handler hijacking via improper validation of protocol names
MEDIUMCVE-2026-34773electron39.2.638.8.6, 39.8.1, 40.8.1, 41.0.0electron: Electron: Protocol handler hijacking via improper validation of protocol names
MEDIUMCVE-2026-34775electron12.0.438.8.6, 39.8.4, 40.8.4, 41.0.0Electron: Electron: Arbitrary code execution and information disclosure due to incorrect Node.js integration scoping
MEDIUMCVE-2026-34775electron39.2.638.8.6, 39.8.4, 40.8.4, 41.0.0Electron: Electron: Arbitrary code execution and information disclosure due to incorrect Node.js integration scoping
MEDIUMCVE-2026-34776electron12.0.438.8.6, 39.8.1, 40.8.1, 41.0.0Electron: Electron: Information disclosure via crafted second-instance message
MEDIUMCVE-2026-34776electron39.2.638.8.6, 39.8.1, 40.8.1, 41.0.0Electron: Electron: Information disclosure via crafted second-instance message
MEDIUMCVE-2026-34777electron12.0.438.8.6, 39.8.1, 40.8.1, 41.0.0Electron: Electron: Unauthorized permission granting and information disclosure via incorrect iframe origin
MEDIUMCVE-2026-34777electron39.2.638.8.6, 39.8.1, 40.8.1, 41.0.0Electron: Electron: Unauthorized permission granting and information disclosure via incorrect iframe origin
MEDIUMCVE-2026-34778electron12.0.438.8.6, 39.8.1, 40.8.1, 41.0.0Electron: Electron: Integrity issue due to IPC channel spoofing by a service worker
MEDIUMCVE-2026-34778electron39.2.638.8.6, 39.8.1, 40.8.1, 41.0.0Electron: Electron: Integrity issue due to IPC channel spoofing by a service worker
MEDIUMCVE-2026-34779electron12.0.438.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
MEDIUMCVE-2026-34779electron39.2.638.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
MEDIUMCVE-2026-70597electron12.0.439.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3Electron: Parent process code-sign check is spoofable
MEDIUMCVE-2026-70597electron39.2.639.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3Electron: Parent process code-sign check is spoofable
MEDIUMCVE-2026-70597electron39.8.539.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3Electron: Parent process code-sign check is spoofable
MEDIUMCVE-2026-70599electron12.0.439.8.7, 40.9.0, 41.2.0, 42.0.0-beta.1Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
MEDIUMCVE-2026-70599electron39.2.639.8.7, 40.9.0, 41.2.0, 42.0.0-beta.1Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
MEDIUMCVE-2026-70599electron39.8.539.8.7, 40.9.0, 41.2.0, 42.0.0-beta.1Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
MEDIUMCVE-2026-70602electron12.0.439.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3Electron: Extension tab APIs operate across session boundaries
MEDIUMCVE-2026-70602electron39.2.639.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3Electron: Extension tab APIs operate across session boundaries
MEDIUMCVE-2026-70602electron39.8.539.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3Electron: Extension tab APIs operate across session boundaries
MEDIUMCVE-2026-70603electron12.0.442.0.0-beta.1, 41.1.1, 40.9.0, 39.8.6Electron: shell.openPath path validation bypass via embedded null byte
MEDIUMCVE-2026-70603electron39.2.642.0.0-beta.1, 41.1.1, 40.9.0, 39.8.6Electron: shell.openPath path validation bypass via embedded null byte
MEDIUMCVE-2026-70603electron39.8.542.0.0-beta.1, 41.1.1, 40.9.0, 39.8.6Electron: shell.openPath path validation bypass via embedded null byte
MEDIUMCVE-2026-70605electron12.0.439.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3Electron: HTTP redirect followed into local file loader
MEDIUMCVE-2026-70605electron39.2.639.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3Electron: HTTP redirect followed into local file loader
MEDIUMCVE-2026-70605electron39.8.539.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3Electron: HTTP redirect followed into local file loader
MEDIUMCVE-2026-70607electron12.0.439.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3Electron: window.open features string controls some window options considered privileged
MEDIUMCVE-2026-70607electron39.2.639.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3Electron: window.open features string controls some window options considered privileged
MEDIUMCVE-2026-70607electron39.8.539.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3Electron: window.open features string controls some window options considered privileged
MEDIUMCVE-2026-70609electron12.0.439.8.7, 40.9.0, 41.2.0, 42.0.0-beta.1Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
MEDIUMCVE-2026-70609electron39.2.639.8.7, 40.9.0, 41.2.0, 42.0.0-beta.1Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
MEDIUMCVE-2026-70609electron39.8.539.8.7, 40.9.0, 41.2.0, 42.0.0-beta.1Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
MEDIUMCVE-2026-70610electron12.0.439.8.9, 40.9.2, 41.2.2, 42.0.0-beta.4Electron: contextBridge object copy honors prototype setters
MEDIUMCVE-2026-70610electron39.2.639.8.9, 40.9.2, 41.2.2, 42.0.0-beta.4Electron: contextBridge object copy honors prototype setters
MEDIUMCVE-2026-70610electron39.8.539.8.9, 40.9.2, 41.2.2, 42.0.0-beta.4Electron: contextBridge object copy honors prototype setters
MEDIUMCVE-2026-70611electron12.0.439.8.9, 40.9.2, 41.2.1, 42.0.0-beta.3Electron: DevTools embedder handler executes arbitrary files via shell open
MEDIUMCVE-2026-70611electron39.2.639.8.9, 40.9.2, 41.2.1, 42.0.0-beta.3Electron: DevTools embedder handler executes arbitrary files via shell open
MEDIUMCVE-2026-70611electron39.8.539.8.9, 40.9.2, 41.2.1, 42.0.0-beta.3Electron: DevTools embedder handler executes arbitrary files via shell open
MEDIUMCVE-2026-70612electron12.0.439.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3Electron: Sandboxed iframes can launch external protocol handlers
MEDIUMCVE-2026-70612electron39.2.639.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3Electron: Sandboxed iframes can launch external protocol handlers
MEDIUMCVE-2026-70612electron39.8.539.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3Electron: Sandboxed iframes can launch external protocol handlers
MEDIUMCVE-2025-64718js-yaml4.1.04.1.1, 3.14.2js-yaml: js-yaml prototype pollution in merge
MEDIUMCVE-2026-53550js-yaml4.1.04.2.0, 3.15.0js-yaml: js-yaml: Denial of Service via crafted YAML merge keys
MEDIUMCVE-2025-66400mdast-util-to-hast13.0.013.2.1mdast-util-to-hast: mdast-util-to-hast: Markdown code elements can appear as regular page content
MEDIUMCVE-2026-14643undici8.7.07.29.0, 8.9.0undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing
MEDIUMCVE-2026-15157undici8.7.06.28.0, 7.29.0, 8.9.0undici: undici: HTTP header injection via unvalidated blob-like body type property
MEDIUMCVE-2026-16728undici8.7.06.28.0, 7.29.0, 8.9.0undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length
MEDIUMCVE-2026-16729undici8.7.06.28.0, 7.29.0, 8.9.0undici: Undici: Cookie attribute injection allows bypassing security protections
LOWCVE-2022-21718electron12.0.413.6.6, 14.2.4, 15.3.5, 16.0.6, 17.0.0-alpha.6Renderers can obtain access to random bluetooth device without permission in Electron
LOWCVE-2022-29247electron12.0.415.5.5, 16.2.6, 17.2.0, 18.0.0-beta.6Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled
LOWCVE-2026-34764electron39.2.639.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5Electron: Electron: Memory corruption or crash due to use-after-free in offscreen rendering with shared textures.
LOWCVE-2026-34766electron12.0.438.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8Electron: Electron: Unauthorized USB device access via select-usb-device event callback validation bypass
LOWCVE-2026-34766electron39.2.638.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8Electron: Electron: Unauthorized USB device access via select-usb-device event callback validation bypass
LOWCVE-2026-34768electron12.0.438.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8electron: Electron: Arbitrary code execution via unquoted path in Run registry key
LOWCVE-2026-34768electron39.2.638.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8electron: Electron: Arbitrary code execution via unquoted path in Run registry key
LOWCVE-2026-34781electron12.0.439.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5Electron: Electron: Denial of Service via malformed clipboard image data
LOWCVE-2026-34781electron39.2.639.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5Electron: Electron: Denial of Service via malformed clipboard image data
LOWCVE-2026-70598electron12.0.439.8.10, 40.9.0, 41.2.1, 42.0.0-beta.3Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
LOWCVE-2026-70598electron39.2.639.8.10, 40.9.0, 41.2.1, 42.0.0-beta.3Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
LOWCVE-2026-70598electron39.8.539.8.10, 40.9.0, 41.2.1, 42.0.0-beta.3Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
LOWCVE-2026-70600electron12.0.439.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3Electron: Cross-origin iframe can position native autofill popup
LOWCVE-2026-70600electron39.2.639.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3Electron: Cross-origin iframe can position native autofill popup
LOWCVE-2026-70600electron39.8.539.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3Electron: Cross-origin iframe can position native autofill popup

Full report (JSON)

Previous scans

Daily Trivy refresh. Current report plus the last 14 full scans; older copies are deleted.

ScannedVuln DBVersionWrapVendorReport
2026-09-02 14:02 UTC2026-09-010.0.37none28 HIGH · 65 MEDIUM · 15 LOWJSON
2026-09-02 06:51 UTC2026-09-010.0.37none28 HIGH · 65 MEDIUM · 15 LOWJSON
2026-09-02 04:58 UTC2026-09-010.0.37none28 HIGH · 65 MEDIUM · 15 LOWJSON
2026-09-02 04:31 UTC2026-09-010.0.37none28 HIGH · 65 MEDIUM · 15 LOWJSON
2026-09-02 03:57 UTC2026-09-010.0.37none28 HIGH · 65 MEDIUM · 15 LOWJSON
2026-09-02 03:44 UTC2026-09-010.0.37none28 HIGH · 65 MEDIUM · 15 LOWJSON
2026-09-02 01:42 UTC2026-09-010.0.37none28 HIGH · 65 MEDIUM · 15 LOWJSON
2026-09-01 07:28 UTC2026-09-010.0.37none28 HIGH · 65 MEDIUM · 15 LOWJSON
2026-09-01 06:51 UTC2026-09-010.0.36none28 HIGH · 65 MEDIUM · 15 LOWJSON
2026-08-31 09:28 UTC2026-08-310.0.36none28 HIGH · 65 MEDIUM · 15 LOWJSON
2026-08-31 07:28 UTC2026-08-310.0.36none28 HIGH · 65 MEDIUM · 15 LOWJSON
2026-08-31 06:51 UTC2026-08-310.0.36none28 HIGH · 65 MEDIUM · 15 LOWJSON
2026-08-30 07:29 UTC2026-08-300.0.36none28 HIGH · 65 MEDIUM · 15 LOWJSON
2026-08-30 06:51 UTC2026-08-300.0.35none28 HIGH · 65 MEDIUM · 15 LOWJSON