Sceawere

Vulnerability Detail

CVE-2026-86334UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

LXD CLI Path Traversal Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.2
Creation Date
3h ago
Vendor
Canonical
Product
LXD
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
Attack Complexity
HIGH

Narrative and Response

Description

Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.2",
  "pubDate": "2026-09-28T14:17:20.590Z",
  "pubdate": "2026-09-28T14:17:20.590Z",
  "executiveSummary": "A critical path traversal vulnerability exists in the Canonical LXD CLI client during image export and copy operations. This flaw allows a remote malicious or machine-in-the-middle (MITM) image server to manipulate the file system of the host running the LXD client.\nThe vulnerability type is improper neutralization of special elements used in a pathname (Path Traversal). By exploiting a crafted Content-Disposition header, an attacker can coerce the LXD client to write arbitrary files to the local file system. This capability permits the overwrite of critical system files, potentially leading to arbitrary code execution with the privileges of the user running the CLI tool.\nThe impact is severe, as it facilitates remote compromise of the client system. Affected versions include Canonical LXD 4.0.2 through 4.0.13, versions prior to 5.0.10, 5.21.8, and 6.1.0. Mitigation requires updating to the patched versions provided by Canonical to ensure proper sanitization of file paths derived from external image server metadata.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient validation of the 'filename' parameter provided within the HTTP 'Content-Disposition' header during LXD unified image export or copy operations. When the LXD CLI client initiates a download or transfer from an image server, it processes metadata headers to determine the target path for saving the image artifacts.\nThe vulnerability manifests because the LXD client fails to sanitize or validate the filename string against directory traversal sequences (e.g., '../'). An attacker operating a rogue image server, or an adversary positioned to perform a MITM attack, can intercept the request and inject path traversal sequences into the 'Content-Disposition' header. When the client parses this header, the lack of input validation allows the application to write files outside the intended destination directory.\nThe attack flow follows these steps: 1) The victim executes an LXD CLI command to export or copy an image from a remote source. 2) The malicious server responds to the client's request with a crafted 'Content-Disposition: attachment; filename=\"../../../../etc/shadow\"' (or similar sensitive target) header. 3) The LXD CLI client, failing to normalize or restrict the path, treats the filename as a legitimate destination relative to the current working directory or the configured target directory. 4) The application writes the image payload to the attacker-specified path. 5) Through the overwrite of configuration files, binaries, or SSH keys, the attacker achieves arbitrary code execution or local privilege escalation on the host system.\nThis vulnerability affects LXD versions 4.0.2 up to 4.0.13, versions before 5.0.10, 5.21.8, and 6.1.0. The exploit does not require prior authentication to the target system, as the attack is initiated by the client's interaction with a malicious server. The network exposure is limited to the client-server interaction during the image retrieval process. Post-exploitation, the attacker gains the ability to overwrite files with the permissions of the user invoking the LXD CLI, potentially leading to full system compromise if the command is executed with elevated privileges."
}
CVE-2026-86334: LXD CLI Path Traversal Vulnerability (MEDIUM Severity, CVSS: 4.2) | Sceawere