Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-48752: Incus allows malicious images to read and write host files
GHSA-vxp5-584q-c479
CVE-2026-48752
GO-2026-5803
Summary
Incus, a container management software, can be tricked into allowing malicious images to read and write files on the host system. This could potentially allow an attacker to execute malicious code on the host. To protect against this, ensure that you only import trusted images into Incus and consider implementing additional security measures to restrict file access.
What to do
- Update github.com lxc to version 7.2.0.
- Update lxc github.com/lxc/incus/v7 to version 7.2.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| go | github.com | lxc |
< 7.2.0 Fix: upgrade to 7.2.0
|
| Go | lxc | github.com/lxc/incus | All versions |
| Go | lxc | github.com/lxc/incus/v6 | All versions |
| Go | lxc | github.com/lxc/incus/v7 |
< 7.2.0 Fix: upgrade to 7.2.0
|
Original title
Incus has arbitrary file read+write on host via templates/ symlink in malicious image in github.com/lxc/incus
Original description
Incus has arbitrary file read+write on host via templates/ symlink in malicious image in github.com/lxc/incus
ghsa CVSS3.1
9.9
Vulnerability type
CWE-73
Published: 7 Jul 2026 · Updated: 7 Jul 2026 · First seen: 26 Jun 2026