Thursday, October 1, 2026
Follow on LinkedIn

CopyEscape Docker Flaw Lets Malicious Containers Overwrite Host Files and Gain Root Access

A Docker flaw, CVE-2026-17106 (dubbed CopyEscape), lets malicious containers write files outside the docker cp destination, potentially enabling code execution and root-level compromise.

The issue affects Docker’s archive extraction handling in moby/go-archive. When users copy files from a container to a host, Docker does not perform a simple direct transfer.

The Docker daemon first packages the requested container files into a tar archive, and the local Docker CLI extracts that archive using the permissions of the user who ran the command.

That process becomes dangerous when an attacker controls the source container. A normal command such as docker cp container:/report.txt ./report.txt appears safe because the user chooses the destination.

However, CopyEscape allows an attacker to manipulate the archive created by a running container and plant a symlink that points outside the chosen output directory.

Docker Tar Processing Flow (source : imperva )
Docker Tar Processing Flow (source : imperva )

The Docker CLI can then follow that symlink while extracting a later archive entry, causing the file write to land elsewhere on the host filesystem.

CopyEscape Docker Flaw

Imperva said the exploit chain combines two weaknesses. First, a time-of-check to time-of-use race in the archive-generation process lets a running container change a directory into a symbolic link while Docker is walking its filesystem.

This can produce an inconsistent tar archive that describes the same path as both a directory and a symlink. Second, vulnerable extraction routines do not reliably confine writes to the destination folder after filesystem links are resolved.

The result is an arbitrary file creation or overwrite primitive with the permissions of the Docker CLI process. A developer who runs Docker cp could have shell startup files, SSH configuration, cloud credentials, source code, or user-level persistence files replaced.

The source filesystem shows escape as a symlink, but its child treats it as a directory (source : imperva )
The source filesystem shows escape as a symlink, but its child treats it as a directory (source : imperva )

On macOS, the vulnerable extraction occurs on the local system even though Docker Desktop runs containers inside a Linux virtual machine, making local user files a potential target.

The risk is more serious on Linux systems where administrators, CI systems, maintenance scripts, or automated pipelines run sudo docker cp. In its proof of concept, Imperva replaced /usr/bin/runc with an attacker-controlled script.

According to Imperva, once Docker later invoked the replaced runtime binary, the payload executed as root. The attack does not directly grant the container Docker daemon privileges instead, it abuses the elevated authority already granted to the docker cp command.

CVE-2026-17106 also affects Docker Sandboxes through sbx cp, creating risks for AI-agent and coding-agent workflows when retrieving files from untrusted sandboxes. Docker Sandboxes 0.38.0 fixes the destination-escape issue.

Docker addressed the flaw in Docker Desktop 4.86.0, released on August 10, 2026. The release notes describe the issue as a destination-escape flaw in docker container cp. The underlying moby/go-archive fix is available in version 0.3.0, while the affected package versions are earlier than 0.3.0.

Organizations should upgrade Docker Desktop to version 4.86.0 or later and update Docker Engine and Docker CLI to current patched releases. Docker’s security advisory confirms that Desktop 4.86.0 fixes CVE-2026-17106.

Until upgrades are complete, administrators should avoid copying files from running containers that are untrusted, compromised, or used for processing external content.

Stopping a container before using docker cp can prevent the live filesystem race used in the demonstrated exploit. However, treat all archives from untrusted sources as hostile.

Teams should also avoid sudo docker cp, remove root privileges from CI artifact-collection jobs where possible, and retrieve suspicious container data only from disposable virtual machines or isolated analysis environments.

CopyEscape shows that archive extraction is itself a security boundary: a routine file-retrieval operation can become the path an attacker uses to cross from a container back onto the host.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Abinaya
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Cyber Security Guide

Latest Cyber News

Expert Talks