—
GO-2026-4357
Incus container image templating arbitrary host file read and write in github.com/lxc/incus
Details
Incus container image templating arbitrary host file read and write in github.com/lxc/incus
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/lxc/incus
Introduced in:
0No fixed version published yet for github.com/lxc/incus (go modules). Pin to a known-safe version or switch to an alternative.
Go/github.com/lxc/incus/v6
Introduced in:
6.1.0No fixed version published yet for github.com/lxc/incus/v6 (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/lxc/incus/security/advisories/GHSA-7f67-crqm-jgh7[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-23954[ADVISORY]
- https://github.com/lxc/incus/blob/HEAD/internal/server/instance/drivers/driver_lxc.go#L7215[WEB]
- https://github.com/lxc/incus/blob/HEAD/internal/server/instance/drivers/driver_lxc.go#L7294[WEB]
- https://github.com/user-attachments/files/24473599/template_arbitrary_write.sh[WEB]
- https://github.com/user-attachments/files/24473601/templates_arbitrary_write.patch[WEB]