CVE-2021-41089Low· 2.8▾ Sunlit`docker cp` allows unexpected chmod of host files in Moby Docker Engine
▾ Sunlit zone — Low / medium · no exploitation signal
impact 15.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.3%
A bug was found in Moby (Docker Engine) where attempting to copy files using docker cp into a specially-crafted container can result in Unix file permission changes for existing files in the host’s filesystem, widening access to others. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process.
This bug has been fixed in Moby (Docker Engine) 20.10.9. Users should update to this version as soon as possible. Running containers do not need to be restarted.
Ensure you only run trusted containers.
The Moby project would like to thank Lei Wang and Ruizhi Xiao for responsibly disclosing this issue in accordance with the Moby security policy.
If you have any questions or comments about this advisory:
github.com/docker/docker < 20.10.9Upgrade to a patched release:
github.com/docker/docker 20.10.9Connected by shared product, vendor, weakness, or advisory.
CVE-2021-41092Medium· 5.4Docker CLI leaks private registry credentials to registry-1.docker.io
CVE-2026-41568NoneRace condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files
GO-2022-0379NoneType confusion in github.com/docker/distribution
GHSA-qq97-vm5h-rrhgLow· 3.0OCI Manifest Type Confusion Issue
CVE-2026-55887High· 8.7MCP Gateway allows easy and secure running and deployment of MCP servers
CVE-2026-79994High· 8.7The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname