CopyEscape Docker Flaw Lets Malicious Containers Overwrite Host Files and Gain Root Access
CopyEscape, CVE-2026-17106, lets malicious containers overwrite host files through Docker's archive copy path.
Imperva disclosed CopyEscape, CVE-2026-17106, in Docker's moby/go-archive handling used by docker cp. A time-of-check/time-of-use race lets a running container turn a directory into a symlink while the archive is built, and vulnerable extraction can then write outside the chosen host destination with the Docker CLI user's permissions. Imperva's proof of concept replaced /usr/bin/runc so a later runtime invocation executed an attacker script as root. Docker fixed Desktop in 4.86.0 on August 10, 2026, go-archive in 0.3.0, and Sandboxes in 0.38.0; active exploitation is not reported.