Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-48752: Incus allows malicious images to read and write host files

GHSA-vxp5-584q-c479 CVE-2026-48752 GO-2026-5803
Summary

Incus, a container management software, can be tricked into allowing malicious images to read and write files on the host system. This could potentially allow an attacker to execute malicious code on the host. To protect against this, ensure that you only import trusted images into Incus and consider implementing additional security measures to restrict file access.

What to do
  • Update github.com lxc to version 7.2.0.
  • Update lxc github.com/lxc/incus/v7 to version 7.2.0.
Affected software
Ecosystem VendorProductAffected versions
go github.com lxc < 7.2.0
Fix: upgrade to 7.2.0
Go lxc github.com/lxc/incus All versions
Go lxc github.com/lxc/incus/v6 All versions
Go lxc github.com/lxc/incus/v7 < 7.2.0
Fix: upgrade to 7.2.0
Original title
Incus has arbitrary file read+write on host via templates/ symlink in malicious image in github.com/lxc/incus
Original description
Incus has arbitrary file read+write on host via templates/ symlink in malicious image in github.com/lxc/incus
ghsa CVSS3.1 9.9
Vulnerability type
CWE-73
Published: 7 Jul 2026 · Updated: 7 Jul 2026 · First seen: 26 Jun 2026