Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-48750: Incus containers can write files to host system

CVE-2026-48750 · published 13 days ago
Summary

Incus lets a container specify where command output is saved. If a container tricks Incus into using a symbolic link, it can place files anywhere on the host, such as the system's cron directory, and run its own commands. Update Incus to the latest version or apply the vendor's patch and avoid using untrusted container images.

What to do
  • Update lxc github.com/lxc/incus/v7 to version 7.2.0.
  • Update github.com lxc to version 7.2.0.
  • Update debian incus to version 6.0.4-2+deb13u8.
  • Update debian incus to version 7.0.0-5.
  • Update debian lxd to version 5.0.2+git20231211.1364ae4-9+deb13u7.
Affected software
Ecosystem VendorProductAffected versions
Go lxc github.com/lxc/incus/v6 All versions
Go lxc github.com/lxc/incus/v7 < 7.2.0
Fix: upgrade to 7.2.0
Debian:13 debian incus < 6.0.4-2+deb13u8
Fix: upgrade to 6.0.4-2+deb13u8
Debian:14 debian incus < 7.0.0-5
Fix: upgrade to 7.0.0-5
Debian:12 debian lxd All versions
Debian:13 debian lxd < 5.0.2+git20231211.1364ae4-9+deb13u7
Fix: upgrade to 5.0.2+git20231211.1364ae4-9+deb13u7
go github.com lxc < 7.2.0
Fix: upgrade to 7.2.0
Go lxc github.com/lxc/incus All versions
– lxc incus < 7.2.0
Ubuntu:Pro:16.04:LTS canonical lxd All versions
Ubuntu:Pro:18.04:LTS canonical lxd All versions
Ubuntu:20.04:LTS canonical lxd All versions
Ubuntu:Pro:24.04:LTS canonical incus All versions
Ubuntu:25.10 canonical incus All versions
Ubuntu:Pro:26.04:LTS canonical incus All versions
Original advisory text
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-...
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output` is a symlink, file named `exec_UUID.stdout` and `exec_UUID.stderr` can be written to an arbitrary location where the `.stdout` file will contain arbitrary content. This behavior can be abused for arbitrary command execution. Version 7.2.0 contains a patch.
Severity
9.9 Critical
CVSS 3.1: 9.9 (GHSA)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-73External Control of File Name or Path
Timeline
Published21 Aug 2026
Updated3 Sep 2026
First seen26 Jun 2026
Monitor software like this
Free during beta