Link following in LXD - CVE-2026-48750
Published: June 29, 2026
LXD
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code on the host.
The vulnerability exists due to improper link resolution in the /instances/$name/exec endpoint exec-output handling when processing the record-output parameter for a crafted image. A remote user can create an instance from a crafted image and invoke exec with record-output enabled to execute arbitrary code on the host.
The issue arises because a top-level exec-output symlink from the image can be extracted as is, causing stdout and stderr files to be written to an arbitrary host location.