Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-48753: Incus S3 Multipart Upload allows arbitrary file creation
GHSA-ccjc-4qc3-jxqc
CVE-2026-48753
GO-2026-5802
Summary
A vulnerability in Incus's S3 protocol upload endpoint allows attackers to create arbitrary files on the host, potentially leading to unauthorized command execution. This affects Incus users who rely on S3 multipart uploads. To mitigate this issue, update to the latest version of Incus or apply the necessary patches.
What to do
- Update github.com lxc to version 7.1.0.
- Update lxc github.com/lxc/incus/v7 to version 7.1.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| go | github.com | lxc |
< 7.1.0 Fix: upgrade to 7.1.0
|
| Go | lxc | github.com/lxc/incus | All versions |
| Go | lxc | github.com/lxc/incus/v6 | All versions |
| Go | lxc | github.com/lxc/incus/v7 |
< 7.1.0 Fix: upgrade to 7.1.0
|
Original title
Incus has an arbitrary file write via path traversal in S3 multipart upload in github.com/lxc/incus
Original description
Incus has an arbitrary file write via path traversal in S3 multipart upload in github.com/lxc/incus
ghsa CVSS3.1
9.9
Vulnerability type
CWE-73
Published: 7 Jul 2026 · Updated: 7 Jul 2026 · First seen: 26 Jun 2026