Path traversal in LXD - CVE-2026-86334
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to overwrite arbitrary files on the client.
The vulnerability exists due to path traversal in the unified image export and copy handling of the CLI when processing a server-controlled Content-Disposition filename for an image exported to a directory target. A remote attacker can provide a crafted filename containing path traversal sequences to overwrite files outside the export directory.
User interaction is required because the victim must export or copy an image from the malicious server to a directory target.