github.com/lxc/incus/v7/cmd/incusd
Go9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/lxc/incus/v7/cmd/incusdpage 1 of 1
- CVE-2026-48749CRITICALCVSS 9.9EG 9.9✓ Fixed in 7.2.02026-06-26
Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image ### Summary A specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution.…
- CVE-2026-48750CRITICALCVSS 9.9EG 9.9✓ Fixed in 7.2.02026-06-26
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image ### Summary The `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the…
- CVE-2026-48751CRITICALCVSS 9.9EG 9.9✓ Fixed in 7.2.02026-06-26
Incus has a restricted project bypass leading to arbitrary command execution ### Summary Instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusin…
- CVE-2026-48752CRITICALCVSS 9.9EG 9.9✓ Fixed in 7.2.02026-06-26
Incus has arbitrary file read+write on host via templates/ symlink in malicious image ### Summary A specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary…
- CVE-2026-48753CRITICALCVSS 9.9EG 9.9✓ Fixed in 7.1.02026-06-26
Incus has an arbitrary file write via path traversal in S3 multipart upload ## Summary The S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitr…
- CVE-2026-48754LOWEG 0.0✓ Fixed in 7.1.02026-06-26
Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool} ## Summary `(*backend).createDependentVolumesFromBackup` in [`internal/server/storage/backend.go`](https://github.com/lxc/incus/blo…
- CVE-2026-48755CRITICALCVSS 9.9EG 9.9✓ Fixed in 7.2.02026-06-26
Incus has an argument injection in backup compression algorithm leading to AFW and ACE ### Summary Improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads …
- CVE-2026-48756LOWEG 0.0✓ Fixed in 7.1.02026-06-26
Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7) ## Summary `(*backend).CreateCustomVolumeFromBackup` in [`internal/server/storage/backend.go`](https://git…
- CVE-2026-48769CRITICALCVSS 9.9EG 9.9✓ Fixed in 7.2.02026-06-26
Incus has an arbitrary file write on its client due to trusted image hash ### Summary An arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrar…
Check whether github.com/lxc/incus/v7/cmd/incusd is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/lxc/incus/v7/cmd/incusd CVEs against the assets you own.
Start Free Scan →