A newly disclosed Docker vulnerability, tracked as CVE-2026-17106 and nicknamed “CopyEscape,” allows malicious containers to overwrite files on the host machine and, in certain configurations, achieve full root code execution. The flaw was discovered by the Imperva Red Team and affects the widely used docker cp command, along with the related sbx cp command used in Docker Sandboxes for AI-agent workflows. If exploited, CopyEscape allows a malicious container to escape its isolated environment, write or overwrite arbitrary files on the client host, and, under specific conditions on Linux, achieve root-level code execution. CopyEscape Docker Vulnerability Enables Root Access The vulnerability lives inside...
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!