Vulnerability Description
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml file pointing to target file paths on the host system.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Lxd | >= 4.0.0, < 4.0.12 |
Related Weaknesses (CWE)
References
- https://github.com/canonical/lxd/security/advisories/GHSA-j825-cg34-5fr5Vendor AdvisoryExploit
- https://github.com/canonical/lxd/security/advisories/GHSA-j825-cg34-5fr5Vendor AdvisoryExploit
FAQ
What is CVE-2026-63293?
CVE-2026-63293 is a vulnerability with a CVSS score of 9.9 (CRITICAL). A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whe...
How severe is CVE-2026-63293?
CVE-2026-63293 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-63293?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Lxd.