Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-48750: Incus allows arbitrary file writes via crafted images

GHSA-73hr-m85f-64v9 CVE-2026-48750 GO-2026-5801
Summary

A vulnerability in Incus allows attackers to write files to arbitrary locations on the host system by creating a specially crafted image. This can potentially lead to unauthorized command execution. To mitigate this issue, ensure that you only import images from trusted sources and consider implementing additional security measures to restrict access to sensitive system directories.

What to do
  • Update github.com lxc to version 7.2.0.
  • Update lxc github.com/lxc/incus/v7 to version 7.2.0.
Affected software
Ecosystem VendorProductAffected versions
go github.com lxc < 7.2.0
Fix: upgrade to 7.2.0
Go lxc github.com/lxc/incus All versions
Go lxc github.com/lxc/incus/v6 All versions
Go lxc github.com/lxc/incus/v7 < 7.2.0
Fix: upgrade to 7.2.0
Original title
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image in github.com/lxc/incus
Original description
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image in github.com/lxc/incus
ghsa CVSS3.1 9.9
Vulnerability type
CWE-73
Published: 7 Jul 2026 · Updated: 7 Jul 2026 · First seen: 26 Jun 2026