CVE Explorer
CVE-2026-23954
Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write. This ultimately results in arbitrary command execution on the host. When using an image with a metadata.yaml containing templates, both the source and target paths
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"incus","vendor":"lxc","versions":[{"status":"affected","version":">= 6.1.0, <= 6.20.0"},{"status":"affected","version":"<= 6.0.5"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:97f2415cb5debdf323c3cc337a13e1c6a6daa411d245f22b940440043c4d5c01 · sha256:74ee3270e274631e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:97f2415cb5debdf323c3cc337a13e1c6a6daa411d245f22b940440043c4d5c01 · sha256:74ee3270e274631e… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:97f2415cb5debdf323c3cc337a13e1c6a6daa411d245f22b940440043c4d5c01 · sha256:74ee3270e274631e… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://github.com/lxc/incus/blob/HEAD/internal/server/instance/drivers/driver_lxc.go#L7215","tags":["x_refsource_MISC"],"url":"https://github.com/lxc/incus/blob/HEAD/internal/server/instance/drivers/driver_lxc.go#L7215"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:97f2415cb5debdf323c3cc337a13e1c6a6daa411d245f22b940440043c4d5c01 · sha256:74ee3270e274631e… · /containers/cna/references/1
{"name":"https://github.com/lxc/incus/blob/HEAD/internal/server/instance/drivers/driver_lxc.go#L7294","tags":["x_refsource_MISC"],"url":"https://github.com/lxc/incus/blob/HEAD/internal/server/instance/drivers/driver_lxc.go#L7294"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:97f2415cb5debdf323c3cc337a13e1c6a6daa411d245f22b940440043c4d5c01 · sha256:74ee3270e274631e… · /containers/cna/references/2
{"name":"https://github.com/lxc/incus/security/advisories/GHSA-7f67-crqm-jgh7","tags":["x_refsource_CONFIRM"],"url":"https://github.com/lxc/incus/security/advisories/GHSA-7f67-crqm-jgh7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:97f2415cb5debdf323c3cc337a13e1c6a6daa411d245f22b940440043c4d5c01 · sha256:74ee3270e274631e… · /containers/cna/references/0
{"name":"https://github.com/user-attachments/files/24473599/template_arbitrary_write.sh","tags":["x_refsource_MISC"],"url":"https://github.com/user-attachments/files/24473599/template_arbitrary_write.sh"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:97f2415cb5debdf323c3cc337a13e1c6a6daa411d245f22b940440043c4d5c01 · sha256:74ee3270e274631e… · /containers/cna/references/3
{"name":"https://github.com/user-attachments/files/24473601/templates_arbitrary_write.patch","tags":["x_refsource_MISC"],"url":"https://github.com/user-attachments/files/24473601/templates_arbitrary_write.patch"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:97f2415cb5debdf323c3cc337a13e1c6a6daa411d245f22b940440043c4d5c01 · sha256:74ee3270e274631e… · /containers/cna/references/4
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.