Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd |
|
| Vendors & Products |
Canonical
Canonical lxd |
Mon, 28 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target. | |
| Title | CLI Path Traversal via Content-Disposition in LXD Image Export/Copy | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-09-28T17:56:11.126Z
Reserved: 2026-09-07T08:01:22.941Z
Link: CVE-2026-86334
Updated: 2026-09-28T17:56:03.588Z
Status : Deferred
Published: 2026-09-28T14:17:20.590
Modified: 2026-09-28T18:17:25.683
Link: CVE-2026-86334
No data.
OpenCVE Enrichment
Updated: 2026-09-28T15:45:02Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')