CVE Explorer
CVE-2026-23953
Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can create an environment variable containing newlines, which can be used to add additional configuration items in the container’s lxc.conf due to newline injection. This can allow adding arbitrary lifecycle hooks, ultimately resulting in arbitrary command execution on the host. Exploiting this is
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"incus","vendor":"lxc","versions":[{"status":"affected","version":">= 6.1.0, <= 6.20.0"},{"status":"affected","version":"<= 6.0.5"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:86044c25a3b9946e1fc563cb8f3b1156175693a1189ff966efddf799b57025da · sha256:9412085e34435c56… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:86044c25a3b9946e1fc563cb8f3b1156175693a1189ff966efddf799b57025da · sha256:9412085e34435c56… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-93","description":"CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:86044c25a3b9946e1fc563cb8f3b1156175693a1189ff966efddf799b57025da · sha256:9412085e34435c56… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/lxc/incus/blob/HEAD/internal/server/instance/drivers/driver_lxc.go#L1081","tags":["x_refsource_MISC"],"url":"https://github.com/lxc/incus/blob/HEAD/internal/server/instance/drivers/driver_lxc.go#L1081"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:86044c25a3b9946e1fc563cb8f3b1156175693a1189ff966efddf799b57025da · sha256:9412085e34435c56… · /containers/cna/references/1
{"name":"https://github.com/lxc/incus/security/advisories/GHSA-x6jc-phwx-hp32","tags":["x_refsource_CONFIRM"],"url":"https://github.com/lxc/incus/security/advisories/GHSA-x6jc-phwx-hp32"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:86044c25a3b9946e1fc563cb8f3b1156175693a1189ff966efddf799b57025da · sha256:9412085e34435c56… · /containers/cna/references/0
{"name":"https://github.com/user-attachments/files/24473682/environment_newline_injection.sh","tags":["x_refsource_MISC"],"url":"https://github.com/user-attachments/files/24473682/environment_newline_injection.sh"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:86044c25a3b9946e1fc563cb8f3b1156175693a1189ff966efddf799b57025da · sha256:9412085e34435c56… · /containers/cna/references/2
{"name":"https://github.com/user-attachments/files/24473685/environment_newline_injection.patch","tags":["x_refsource_MISC"],"url":"https://github.com/user-attachments/files/24473685/environment_newline_injection.patch"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:86044c25a3b9946e1fc563cb8f3b1156175693a1189ff966efddf799b57025da · sha256:9412085e34435c56… · /containers/cna/references/3
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.