Docker CopyEscape CVE-2026-17106 (CVSS 4.0 7.1): malicious container → host file write via docker cp — Imperva/CSN 1 Oct; patch Desktop 4.86.0 / Engine 29.7.0
CVE-2026-17106 (GHSA-hfg8-hc9c-6c3h; Docker/Moby; published mid-August 2026; dubbed CopyEscape): tar extraction in moby/go-archive (Unpack/UnpackLayer/Untar and ApplyLayer helpers) does not confine filesystem writes to the destination directory — lexical path checks can be defeated when archive entries introduce links the OS then follows. An attacker who controls a running container can race docker cp archive generation (directory → symlink TOCTOU) so the host-side CLI extracts attacker-chosen files outside the user-selected destination with the privileges of the docker cp process (including sudo docker cp → root on Linux; macOS Desktop extracts on the host even though containers run in a Linux VM). Imperva research (Ron Masas; Cyber Security News 1 Oct 2026) shows the chain replacing host binaries such as runc so a later Docker runtime invoke runs attacker code as root; also affects Docker Sandboxes sbx cp for AI-agent workflows pulling files from untrusted sandboxes. CVSS 4.0 7.1 HIGH (AV:L/AC:L/AT:P/PR:N/UI:A/…). Fixed: moby/go-archive 0.3.0; Docker Engine/CLI 29.7.0; Docker Desktop 4.86.0 (10 Aug 2026 notes: destination-escape in docker container cp); Docker Compose 5.4.0; Docker Sandboxes 0.38.0. Until patched: do not docker cp from untrusted/compromised containers; stop the container before copy; avoid sudo docker cp in CI. Primary: GHSA / Docker Engine 29 notes; wire: Cyber Security News 1 Oct.
- Product
- Docker Engine / CLI / Desktop / Compose / Sandboxes (moby/go-archive tar extraction)
- Versions
- Affected: moby/go-archive < 0.3.0 (GHSA also notes <0.2.2 in affected range text); Docker Engine/CLI before 29.7.0; Docker Desktop before 4.86.0; Docker Compose before 5.4.0; Docker Sandboxes before 0.38.0 (per CVE.report CNA / Docker notes). Fixed: go-archive 0.3.0; Engine/CLI 29.7.0+; Desktop 4.86.0+; Compose 5.4.0+; Sandboxes 0.38.0+.
- CVSS
- (CVSS 4.0 HIGH; Docker/GHSA)
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - Exploited in Australia?
- unknown
- Patch to
- Upgrade Docker Desktop to 4.86.0+, Engine/CLI to 29.7.0+, Compose to 5.4.0+, Sandboxes to 0.38.0+ (go-archive 0.3.0). Until then: never docker cp / sbx cp from untrusted running containers; prefer stopped containers and non-root artifact collection; isolate untrusted archive extraction.
Primary: GitHub Advisory GHSA-hfg8-hc9c-6c3h — CVE-2026-17106 moby/go-archive destination escape · Vendor: Docker Engine 29 release notes — go-archive v0.3.0 / CVE-2026-17106 · CVE: CVE-2026-17106 · Cyber Security News — CopyEscape Docker flaw (CVE-2026-17106) (1 Oct 2026)
