Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-63293: LXD: Untrusted Image Can Read/Write Host Files as Root

CVE-2026-63293 · published 22 days ago
Summary

LXD, a Linux container manager, has a vulnerability that allows an attacker to access and modify files on the host system by importing a specially crafted image. This could lead to unauthorized data access or modification. To protect your system, ensure you only import images from trusted sources.

What to do
  • Update canonical lxd to version 4.0.12 or later.
Affected software
Ecosystem VendorProductAffected versions
Debian:12 debian lxd All versions
Debian:13 debian lxd All versions
– canonical lxd < 4.0.12
Original advisory text
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate ...
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml file pointing to target file paths on the host system.
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-59Link Following
Timeline
Published12 Aug 2026
Updated30 Aug 2026
First seen13 Aug 2026
Sources
CVE-2026-63293 · MITRE
Monitor software like this
Free during beta