CopyEscape Docker Flaw Lets Malicious Containers Overwrite Host Files and Gain Root Access
CopyEscape, CVE-2026-17106, lets malicious containers overwrite host files through Docker's archive copy path.
Imperva disclosed CopyEscape, CVE-2026-17106, in Docker's moby/go-archive handling used by docker cp. A time-of-check/time-of-use race lets a running container turn a directory into a symlink while the archive is built, and vulnerable extraction can then write outside the chosen host destination with the Docker CLI user's permissions. Imperva's proof of concept replaced /usr/bin/runc so a later runtime invocation executed an attacker script as root. Docker fixed Desktop in 4.86.0 on August 10, 2026, go-archive in 0.3.0, and Sandboxes in 0.38.0; active exploitation is not reported.
- CVE-2026-17106, CopyEscape, abuses archive extraction during docker cp.
- A container race plants a symlink so later entries write outside the destination.
- Imperva's proof of concept replaced /usr/bin/runc and then ran as root.
- Docker Desktop 4.86.0 and moby/go-archive 0.3.0 contain the fix.
- Docker Sandboxes sbx cp was affected until version 0.38.0.
Vulnerabilities mentionedAll →
- CVE-2026-171067.1<1%Path Traversal via Link Following in Moby go-archive Tar Extractionpublished · Docker / Moby project moby/go-archive (tar extraction routines: Unpack, UnpackLayer, Untar/UntarUncompressed, ApplyLayer helpers)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-17106 | Path Traversal via Link Following in Moby go-archive Tar Extraction The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) fail to confine filesystem operations to the destination directory: entry placement is decided with lexical string checks, but the actual filesystem operations follow OS-resolved paths, so links shipped inside an archive can escape the extraction target. An attacker who controls the contents of an archive being extracted — for example a malicious image layer or a supplied tar handled by Moby-based tooling — can create or overwrite files at arbitrary paths writable by the extracting process. The CVSS 4.0 vector (AV:L, AT:P, UI:A) indicates exploitation requires local access to the extraction context plus certain preconditions, rather than remote unauthenticated access. Anyone running software that embeds the vulnerable moby/go-archive routines, notably Moby/Docker-based container engines that apply image layers or unpack untrusted archives, is potentially affected. There is no evidence of exploitation so far: no public proof-of-concept, not listed in CISA KEV, and EPSS puts 30-day exploitation probability at 0.3%. |
Full article669 words · extracted from cybersecuritynews.com · click to collapse
A Docker flaw, CVE-2026-17106 (dubbed CopyEscape), lets malicious containers write files outside the docker cp destination, potentially enabling code execution and root-level compromise.
The issue affects Docker’s archive extraction handling in moby/go-archive. When users copy files from a container to a host, Docker does not perform a simple direct transfer.
The Docker daemon first packages the requested container files into a tar archive, and the local Docker CLI extracts that archive using the permissions of the user who ran the command.
That process becomes dangerous when an attacker controls the source container. A normal command such as docker cp container:/report.txt ./report.txt appears safe because the user chooses the destination.
However, CopyEscape allows an attacker to manipulate the archive created by a running container and plant a symlink that points outside the chosen output directory.

The Docker CLI can then follow that symlink while extracting a later archive entry, causing the file write to land elsewhere on the host filesystem.
CopyEscape Docker Flaw
Imperva said the exploit chain combines two weaknesses. First, a time-of-check to time-of-use race in the archive-generation process lets a running container change a directory into a symbolic link while Docker is walking its filesystem.
This can produce an inconsistent tar archive that describes the same path as both a directory and a symlink. Second, vulnerable extraction routines do not reliably confine writes to the destination folder after filesystem links are resolved.
The result is an arbitrary file creation or overwrite primitive with the permissions of the Docker CLI process. A developer who runs Docker cp could have shell startup files, SSH configuration, cloud credentials, source code, or user-level persistence files replaced.

escape as a symlink, but its child treats it as a directory (source : imperva )On macOS, the vulnerable extraction occurs on the local system even though Docker Desktop runs containers inside a Linux virtual machine, making local user files a potential target.
The risk is more serious on Linux systems where administrators, CI systems, maintenance scripts, or automated pipelines run sudo docker cp. In its proof of concept, Imperva replaced /usr/bin/runc with an attacker-controlled script.
According to Imperva, once Docker later invoked the replaced runtime binary, the payload executed as root. The attack does not directly grant the container Docker daemon privileges instead, it abuses the elevated authority already granted to the docker cp command.
CVE-2026-17106 also affects Docker Sandboxes through sbx cp, creating risks for AI-agent and coding-agent workflows when retrieving files from untrusted sandboxes. Docker Sandboxes 0.38.0 fixes the destination-escape issue.
Docker addressed the flaw in Docker Desktop 4.86.0, released on August 10, 2026. The release notes describe the issue as a destination-escape flaw in docker container cp. The underlying moby/go-archive fix is available in version 0.3.0, while the affected package versions are earlier than 0.3.0.
Organizations should upgrade Docker Desktop to version 4.86.0 or later and update Docker Engine and Docker CLI to current patched releases. Docker’s security advisory confirms that Desktop 4.86.0 fixes CVE-2026-17106.
Until upgrades are complete, administrators should avoid copying files from running containers that are untrusted, compromised, or used for processing external content.
Stopping a container before using docker cp can prevent the live filesystem race used in the demonstrated exploit. However, treat all archives from untrusted sources as hostile.
Teams should also avoid sudo docker cp, remove root privileges from CI artifact-collection jobs where possible, and retrieve suspicious container data only from disposable virtual machines or isolated analysis environments.
CopyEscape shows that archive extraction is itself a security boundary: a routine file-retrieval operation can become the path an attacker uses to cross from a container back onto the host.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.