Threat intelligence dashboard
CVE-2026-86334medium

CLI Path Traversal via Content-Disposition in LXD Image Export/Copy

Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted Content-Disposition header filename parameter during unified image export or copy operations into a local directory target.

Risk score

4.2

CVSS 3.1

Vendor
Canonical
Product
LXD
CWE
CWE-22
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

LXD

Canonical

Platforms: Linux

Version / rangeStatusType
4.0.2 to before 4.0.14affectedsemver
5.0.0 to before 5.0.10affectedsemver
5.21.0 to before 5.21.8affectedsemver
6.0 to before 6.10affectedsemver

Technical metrics

4.2

CVSS 3.1

Severity
medium
Source
canonical
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L