Junglewise Threat Intelligence

CVE-2026-48750: Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec

CVE-2026-48750 · Severity: critical · CVSS 9.9 · Published 2026-08-21

Technologies: github.com/lxc/incus/v7/cmd/incusd (Go), github.com/lxc/incus/v6 (Go), github.com/lxc/incus (Go), github.com/lxc/incus/v7 (Go). Vendors: Go.

Executive brief

Incus is a container and virtual machine management tool. A vulnerability allows an attacker to use a specially crafted container image to write files to the host operating system's filesystem. This could allow an attacker to gain full control over the host server, potentially leading to data theft or service disruption.

Technical details

A vulnerability in Incus (specifically the incusd component) exists where the 'record-output' parameter of the /instances/$name/exec endpoint fails to properly validate the 'exec-output' directory. If a crafted image contains a top-level symlink named 'exec-output' pointing to a host directory (e.g., /etc/cron.d), the 'os.OpenFile' function follows this symlink when recording command output. An attacker with low privileges can trigger this by launching an instance from a malicious image and executing a command with output recording enabled. This results in the creation of .stdout and .stderr files on the host, which can be leveraged for arbitrary command execution on the host system. The issue is fixed in version 7.2.0.

Affected products

  • LXC Incus < 7.2.0

Timeline

  • 2026-06-25: disclosed
  • 2026-06-26: advisory: GHSA-73hr-m85f-64v9 published
  • 7.2.0: patched

References

Related threats