Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-86334— CLI Path Traversal via Content-Disposition in LXD Image Export/Copy

Quick assessment

Affected
Canonical LXD
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Canonical LXD 的 CLI 客户端在 4.0.2 到 4.0.14 之前、5.0.10 之前、5.21.8 之前以及 6.10 之前版本中,其镜像导出和复制功能存在路径遍历漏洞,影响所有平台。该漏洞允许远程恶意镜像服务器或处于中间人位置的服务器,在统一镜像导出或复制操作指向本地目录目标时,通过精心构造的 Content-Disposition 响应头中的 filename 参数,覆盖任意本地文件,并在客户端系统上执行代码。

CVSS 4.2 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86334

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CLI Path Traversal via Content-Disposition in LXD Image Export/Copy
Source: CVE Program / CVE List V5
Vulnerability Description
Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Canonical LXD 4.0.2 ~ 4.0.14 -

II. Public POCs for CVE-2026-86334

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86334

请登录查看更多情报信息。

Other References for CVE-2026-86334 (6)

Same Patch Batch · Canonical · 2026-09-28 · 7 CVEs total

CVE-2026-87799 9.9 CRITICAL Arbitrary file write on LXD host via symlink in migration stream
CVE-2026-85526 9.9 CRITICAL Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipula
CVE-2026-85185 9.6 CRITICAL Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on hos
CVE-2026-97335 7.7 HIGH Incorrect authorization in LXD storage volume API allows reading volumes from other projec
CVE-2026-86335 6.3 MEDIUM LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse
CVE-2026-87798 5.8 MEDIUM LXD client recursive file pull allows directory escape via malicious VM agent

IV. Related Vulnerabilities

V. Comments for CVE-2026-86334

No comments yet


Leave a comment