Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5071 articles · 189145 vulns · 37/41 feeds (7d)
← Back to list
9.9
CVE-2026-63293PATCHED
canonical · lxd

Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root

Description

A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml file pointing to target file paths on the host system.

Affected Products

VendorProductVersions
canonicallxd4.0.0, 5.0.0, 5.21.0, 6.0

References

  • https://github.com/canonical/lxd/security/advisories/GHSA-j825-cg34-5fr5(vdb-entry, vendor-advisory)

Related News (1 articles)

Tier C
VulDB2h ago
CVE-2026-63293 | Canonical LXD up to 4.0.11/5.0.7/5.21.5/6.9 Image Import metadata.yaml symlink
→ No new info (linked only)
CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.0.125.0.85.21.66.10
CWECWE-59
PublishedAug 12, 2026
Trending Score30
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-62420
Cross-project cluster migration bypasses project restrictions via cluster notification flag
Trending: 35
HIGHCVE-2026-63299
Storage volume cross-project move and snapshot restore bypass project disk limits
Trending: 32
CRITICALCVE-2026-63294
Root RCE via image backup.yaml symlink
Trending: 30
CRITICALCVE-2026-66898
Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE
Trending: 30
CRITICALCVE-2026-63297
Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge
Trending: 30

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 12, 2026
Patch Available
Aug 12, 2026
Discovered by ZDM
Aug 12, 2026