Link following in LXD - CVE-2026-48750

 

Link following in LXD - CVE-2026-48750

Published: June 29, 2026


Vulnerability identifier: #VU135800
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-48750
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the host.

The vulnerability exists due to improper link resolution in the /instances/$name/exec endpoint exec-output handling when processing the record-output parameter for a crafted image. A remote user can create an instance from a crafted image and invoke exec with record-output enabled to execute arbitrary code on the host.

The issue arises because a top-level exec-output symlink from the image can be extracted as is, causing stdout and stderr files to be written to an arbitrary host location.


Affected software

LXD
Debian Linux
lxd (Debian package)

How to mitigate CVE-2026-48750

Install security update from vendor's website.

LXD - addressed in versions 4.0.11, 5.0.7, 5.21.5, 6.9
lxd (Debian package) - update to 5.0.2+git20231211.1364ae4-9+deb13u7

External References

Related Security Bulletins