LXD Symlink Escape: Arbitrary File Read/Write via metadata.yaml
CVE-2026-63293 Published on August 12, 2026

Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml file pointing to target file paths on the host system.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-63293 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

What is an insecure temporary file Vulnerability?

The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

CVE-2026-63293 has been classified to as an insecure temporary file vulnerability or weakness.


Products Associated with CVE-2026-63293

Want to know whenever a new CVE is published for Canonical Lxd? stack.watch will email you.

 

Affected Versions

Canonical LXD: