Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-48750: Incus containers can write files to host system
CVE-2026-48750 · published 13 days ago
Summary
Incus lets a container specify where command output is saved. If a container tricks Incus into using a symbolic link, it can place files anywhere on the host, such as the system's cron directory, and run its own commands. Update Incus to the latest version or apply the vendor's patch and avoid using untrusted container images.
What to do
- Update lxc github.com/lxc/incus/v7 to version 7.2.0.
- Update github.com lxc to version 7.2.0.
- Update debian incus to version 6.0.4-2+deb13u8.
- Update debian incus to version 7.0.0-5.
- Update debian lxd to version 5.0.2+git20231211.1364ae4-9+deb13u7.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Go | lxc | github.com/lxc/incus/v6 | All versions |
| Go | lxc | github.com/lxc/incus/v7 |
< 7.2.0 Fix: upgrade to 7.2.0
|
| Debian:13 | debian | incus |
< 6.0.4-2+deb13u8 Fix: upgrade to 6.0.4-2+deb13u8
|
| Debian:14 | debian | incus |
< 7.0.0-5 Fix: upgrade to 7.0.0-5
|
| Debian:12 | debian | lxd | All versions |
| Debian:13 | debian | lxd |
< 5.0.2+git20231211.1364ae4-9+deb13u7 Fix: upgrade to 5.0.2+git20231211.1364ae4-9+deb13u7
|
| go | github.com | lxc |
< 7.2.0 Fix: upgrade to 7.2.0
|
| Go | lxc | github.com/lxc/incus | All versions |
| – | lxc | incus | < 7.2.0 |
| Ubuntu:Pro:16.04:LTS | canonical | lxd | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | lxd | All versions |
| Ubuntu:20.04:LTS | canonical | lxd | All versions |
| Ubuntu:Pro:24.04:LTS | canonical | incus | All versions |
| Ubuntu:25.10 | canonical | incus | All versions |
| Ubuntu:Pro:26.04:LTS | canonical | incus | All versions |
Original advisory text
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-...
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output` is a symlink, file named `exec_UUID.stdout` and `exec_UUID.stderr` can be written to an arbitrary location where the `.stdout` file will contain arbitrary content. This behavior can be abused for arbitrary command execution. Version 7.2.0 contains a patch.
References
- https://security-tracker.debian.org/tracker/CVE-2026-48750 Vendor Advisory
- https://github.com/canonical/lxd/pull/18590 Third Party Advisory
- https://github.com/advisories/GHSA-73hr-m85f-64v9
- https://ubuntu.com/security/CVE-2026-48750 Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-48750 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48750... Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-48750 Third Party Advisory
- https://github.com/lxc/incus/security/advisories/GHSA-73hr-m85f-64v9 Third Party Advisory
Severity
9.9
Critical
CVSS 3.1: 9.9 (GHSA)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-73External Control of File Name or Path
Timeline
Published21 Aug 2026
Updated3 Sep 2026
First seen26 Jun 2026
Sources
DEBIAN-CVE-2026-48750 · OSV
UBUNTU-CVE-2026-48750 · OSV
CVE-2026-48750 · OSV
CVE-2026-48750 · NVD
GHSA-73hr-m85f-64v9 · GHSA
GO-2026-5801 · OSV
CVE-2026-48750 · MITRE
Monitor software like this
Free during beta