Tag
#Arbitrary File Write
newsCRITICAL 9.9
Critical Vulnerability in Incus: Arbitrary File Write Leads to Root Command Execution
A critical vulnerability (CVE-2026-48769, CVSS 9.9) exists in Incus versions prior to 7.2.0, allowing an attacker to write arbitrary files and execute commands as root on the server. This is triggered by a malicious image server returning a crafted 'Incus-Image-Hash' header. Affected users must update to version 7.2.0 or later immediately.
articleHIGH 8.1
Arbitrary File Write Vulnerability in extract-zip: CVE-2026-19693
A high-severity vulnerability (CVE-2026-19693, CVSS 8.1) exists in the extract-zip package, allowing for arbitrary file writes outside the intended destination directory. This issue, classified as CWE-22 and CWE-59, affects versions up to 2.0.1 and has a significant impact on data integrity and availability. Immediate patching is recommended to prevent potential exploitation.