Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-48750: Incus allows arbitrary file writes via crafted images
GHSA-73hr-m85f-64v9
CVE-2026-48750
GO-2026-5801
Summary
A vulnerability in Incus allows attackers to write files to arbitrary locations on the host system by creating a specially crafted image. This can potentially lead to unauthorized command execution. To mitigate this issue, ensure that you only import images from trusted sources and consider implementing additional security measures to restrict access to sensitive system directories.
What to do
- Update github.com lxc to version 7.2.0.
- Update lxc github.com/lxc/incus/v7 to version 7.2.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| go | github.com | lxc |
< 7.2.0 Fix: upgrade to 7.2.0
|
| Go | lxc | github.com/lxc/incus | All versions |
| Go | lxc | github.com/lxc/incus/v6 | All versions |
| Go | lxc | github.com/lxc/incus/v7 |
< 7.2.0 Fix: upgrade to 7.2.0
|
Original title
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image in github.com/lxc/incus
Original description
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image in github.com/lxc/incus
ghsa CVSS3.1
9.9
Vulnerability type
CWE-73
Published: 7 Jul 2026 · Updated: 7 Jul 2026 · First seen: 26 Jun 2026