CVE-2026-63293
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml file pointing to target file paths on the host system.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.48%
- CWE
- CWE-59
- Published
- 2026-08-12
- Last modified
- 2026-08-13
Affected products
- Canonical LXD
- Canonical LXD
- Canonical LXD
- Canonical LXD
Weakness type
Related vulnerabilities
- CVE-2026-11940 — tarfile extraction filter bypass allows escaping the destination directory
- CVE-2026-7374 — Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability
- CVE-2026-63294 — Root RCE via image backup.yaml symlink
- CVE-2026-63125 — Incus vulnerable to root RCE via image backup.yaml symlink
- CVE-2026-57571 — Crawl4AI arbitrary file write via download filename path traversal
- CVE-2026-54352 — Budibase: Arbitrary file read by workspace-builder via PWA-zip symlink upload
- CVE-2026-53476 — Assisted-migration-agent: vddk tarball chained-symlink arbitrary file write
- CVE-2026-19429 — An incomplete patch for CVE-2026-33001 in Jenkins Project Jenkins through LTS 2.555.3 allows an authenticated remote att