Affected by GO-2026-5798
and 7 other vulnerabilities
GO-2026-5798: Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image in github.com/lxc/incus
GO-2026-5799: Incus has a restricted project bypass leading to arbitrary command execution in github.com/lxc/incus
GO-2026-5801: Incus has an arbitrary file write on host via `exec-output` symlink in crafted image in github.com/lxc/incus
GO-2026-5803: Incus has arbitrary file read+write on host via templates/ symlink in malicious image in github.com/lxc/incus
GO-2026-5806: Incus has an arbitrary file write on its client due to trusted image hash in github.com/lxc/incus
GO-2026-5808: Incus has an argument injection in backup compression algorithm leading to AFW and ACE in github.com/lxc/incus
GO-2026-6318: Incus has a project restriction bypass for custom volume copy across projects in github.com/lxc/incus
GO-2026-6319: Incus has a project restriction bypass in instance copy across projects in github.com/lxc/incus
package
Version:
v7.1.0
Opens a new window with list of versions in this module.
Published: May 29, 2026
License: Apache-2.0
Opens a new window with license information.
Imports: 0
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation
¶
type API10Put struct {
CID uint32 `json:"cid" yaml:"cid"`
Port uint32 `json:"port" yaml:"port"`
Certificate string `json:"certificate" yaml:"certificate"`
DevIncus bool `json:"dev_incus" yaml:"dev_incus"`
}
API10Put contains the fields which are needed for the incus-agent to connect to Incus.
Source Files
¶
Click to show internal directories.
Click to hide internal directories.