---
id: CVE-2026-48753
title: Incus is a system container and virtual machine manager
summary: >-
  Incus is a system container and virtual machine manager. Prior to version
  7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and
  allows creation of arbitrary files on the host. This behavior could lead to
  arbitrary co…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-73
vendor: lxc
product: github.com/lxc/incus/v7/cmd/incusd
affected:
  - github.com/lxc/incus/v7/cmd/incusd < 7.1.0
patched:
  - github.com/lxc/incus/v7/cmd/incusd 7.1.0
published: '2026-08-21'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T20:09:01.757'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48753'
references:
  - url: 'https://github.com/lxc/incus/security/advisories/GHSA-ccjc-4qc3-jxqc'
    label: security-advisories@github.com
  - url: 'https://github.com/lxc/incus/security/advisories/GHSA-ccjc-4qc3-jxqc'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://github.com/advisories/GHSA-ccjc-4qc3-jxqc'
tags:
  - nvd
  - ghsa
  - go
epss: 0.00731
epssPercentile: 0.52259
ecosystem: go
ingestedAt: '2026-06-29T13:24:35.287Z'
---

## Overview

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-48753)

Affected packages:

- `github.com/lxc/incus/v7/cmd/incusd < 7.1.0`

Patched in:

- `github.com/lxc/incus/v7/cmd/incusd 7.1.0`

Source: https://github.com/advisories/GHSA-ccjc-4qc3-jxqc
