CRITICAL
Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root
Published Aug 12, 2026
9.9
CRITICALCVSS 3.1
EPSS 0.59%
Description
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml file pointing to target file paths on the host system.
Affected products
-
- Version 4.0.0StatusaffectedConstraints<4.0.12
- Version 5.0.0StatusaffectedConstraints<5.0.8
- Version 5.21.0StatusaffectedConstraints<5.21.6
- Version 6.0StatusaffectedConstraints<6.10
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to LXD version 4.0.12 or later, 5.0.8 or later, or 5.12.6 or later, or 6.10 or later.
Weaknesses (1)
References (1)
- https://github.com/canonical/lxd/security/advisories/GHSA-j825-cg34-5fr5 exploitvdb-entryvendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/canonical/lxd/security/advisories/GHSA-j825-cg34-5fr5 | exploitvdb-entryvendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Aug 12, 2026
Updated Aug 13, 2026
Reserved Jul 16, 2026
Link CVE-2026-63293
CISA Vulnrichment
Updated Aug 13, 2026