CVE-2026-66897: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Canonical LXD
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution.
AI Analysis
Technical Summary
This vulnerability in LXD's instance template processing involves improper limitation of pathname to a restricted directory (CWE-22). Specifically, when processing target template paths specified in metadata.yaml, LXD performs validation against a confined os.Root directory handle but subsequently uses os.Create with an unconfined string path to open and create files. This discrepancy allows attackers with container edit permissions or users launching crafted images to escape directory confinement, overwrite root-owned files on the host, and achieve host root code execution. The vulnerability affects multiple versions of LXD, including 4.0.0, 5.0.0, 5.21.0, 6.0, and version ranges >=4.0.0 <4.0.13, >=5.0.0 <5.0.9, >=5.21.0 <5.21.7, and >=6.0 <6.10. The CVSS v3.1 score is 9.9, indicating critical severity with network attack vector, low attack complexity, requiring privileges, no user interaction, and complete impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows an attacker with container edit permissions or any user launching a crafted image to overwrite arbitrary files on the host system as root. This leads to full host root code execution, compromising the host's confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is currently documented. Until a patch is available, restrict container edit permissions to trusted users only and avoid launching untrusted images.
CVE-2026-66897: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Canonical LXD
Description
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution.
CVSS v3.1
Score 9.9critical
Affected software
pkg:github/LXDRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in LXD's instance template processing involves improper limitation of pathname to a restricted directory (CWE-22). Specifically, when processing target template paths specified in metadata.yaml, LXD performs validation against a confined os.Root directory handle but subsequently uses os.Create with an unconfined string path to open and create files. This discrepancy allows attackers with container edit permissions or users launching crafted images to escape directory confinement, overwrite root-owned files on the host, and achieve host root code execution. The vulnerability affects multiple versions of LXD, including 4.0.0, 5.0.0, 5.21.0, 6.0, and version ranges >=4.0.0 <4.0.13, >=5.0.0 <5.0.9, >=5.21.0 <5.21.7, and >=6.0 <6.10. The CVSS v3.1 score is 9.9, indicating critical severity with network attack vector, low attack complexity, requiring privileges, no user interaction, and complete impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows an attacker with container edit permissions or any user launching a crafted image to overwrite arbitrary files on the host system as root. This leads to full host root code execution, compromising the host's confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is currently documented. Until a patch is available, restrict container edit permissions to trusted users only and avoid launching untrusted images.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- canonical
- Date Reserved
- 2026-07-28T07:41:26.310Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a8c10e2acd9273b49506afb
Added to database: 08/24/2026, 09:37:38 UTC
Last enriched: 08/24/2026, 09:52:06 UTC
Last updated: 08/24/2026, 11:17:17 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.