Executive brief
Incus is a system container and virtual machine manager used to run and manage isolated workloads on a host. A vulnerability in versions before 7.3.0 allows any authenticated user to read or overwrite arbitrary files on the host system as root by crafting a malicious container image with a symlink. An attacker could steal sensitive configuration files, inject backdoors into system cron jobs, or compromise critical operational files.
Technical details
The vulnerability is a path traversal via symlink in the instance metadata API. The root cause is that Incus's tar extraction uses --restrict to prevent following symlinks outside the extraction root, but does not prevent writing symlink entries themselves. The metadata.yaml file at cmd/incusd/instance_metadata.go is then accessed and written without Lstat guards or os.OpenRoot confinement that were previously applied to exec-output and templates/ paths. An authenticated user can craft an image with metadata.yaml pointing to an arbitrary host path (e.g., /etc/cron.d/backdoor), import it, create an instance, and then use PUT /1.0/instances/{name}/metadata to write YAML-formatted content as root to the symlink target, or use GET to read the target file. The vulnerability requires authentication but no special privileges or user interaction. Version 7.3.0 patches the issue.
Affected products
- Incus Incus < 7.3.0
Timeline
- 2026-07-30: disclosed
- 2026-08-21: patched: Version 7.3.0 released