Link following in LXD - CVE-2026-87798
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to write attacker-controlled files to arbitrary paths on the machine running the CLI with the operator's privileges.
The vulnerability exists due to improper handling of inconsistent directory entries in sftpRecursivePullFile when recursively pulling files from a compromised virtual machine. A remote user can return the same entry name with inconsistent file types to write through a previously created symbolic link to arbitrary paths.
User interaction is required because an operator must run a recursive file pull from the compromised virtual machine. Containers are not affected.