CyberRota Analysis
AI-GeneratedIncus, a system container and virtual machine manager, is vulnerable to improper validation of user-provided backup compression algorithms, allowing for argument injection in command line construction. This flaw can result in arbitrary file writes on the host system, potentially enabling arbitrary command execution. Organizations using versions prior to 7.1.0 should prioritize upgrading to mitigate this critical risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. Version 7.1.0 patches the issue.