What is CVE-2026-63293?
CVE-2026-63293 is a link following vulnerability in LXD. When importing or unpacking an image archive, LXD fails to validate if the metadata.yaml file is a symbolic link, allowing an attacker to achieve arbitrary file read and write operations on the host system. Users are advised to update LXD to the latest stable version.
Azərbaycanca: CVE-2026-63293, LXD-də "link following" zəifliyidir. Təcavüzkar xüsusi hazırlanmış image arxivini idxal edərkən metadata.yaml faylının simvolik keçid olub-olmadığını yoxlamadığı üçün host sistemində ixtiyari fayl oxuya və yaza bilər. İstifadəçilərə LXD-ni ən son stabil versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What operations can an attacker perform on the host system by exploiting CVE-2026-63293?
By exploiting CVE-2026-63293, an attacker can achieve arbitrary file read and write operations on the host system.
How does the CVE-2026-63293 vulnerability occur in LXD?
CVE-2026-63293 occurs because LXD fails to validate if the metadata.yaml file is a symbolic link when importing a specially crafted image archive.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.