Critical CopyEscape Docker Flaw Exposes Hosts to Root Access
Key Takeaways A critical vulnerability, CVE-2026-17106 (dubbed “CopyEscape”), has been discovered in Docker’s docker cp command, allowing malicious containers to write files outside...
Key Takeaways
- A critical vulnerability, CVE-2026-17106 (dubbed “CopyEscape”), has been discovered in Docker’s
docker cpcommand, allowing malicious containers to write files outside the intended destination on the host system. - This flaw can lead to arbitrary code execution and root-level compromise of Docker hosts.
- Docker Desktop versions prior to 4.86.0 and moby/go-archive versions prior to 0.3.0 are affected. Docker Sandboxes also had a related issue, fixed in version 0.38.0.
- Patches are available; users should upgrade Docker Desktop to 4.86.0 or later and update Docker Engine and CLI components.
A significant security flaw, tracked as CVE-2026-17106 and dubbed “CopyEscape,” has been identified in Docker’s file copying mechanism. This vulnerability permits a malicious container to bypass the intended destination directory when using the docker cp command, potentially leading to arbitrary file writes, code execution, and ultimately, root access on the host system.
Table Of Content
The core of the problem lies within Docker’s archive extraction process, specifically in the moby/go-archive component. When a user initiates a file transfer from a container to the host using docker cp, the operation is not a simple direct copy. Instead, the Docker daemon first packages the requested files from the container into a tar archive. Subsequently, the local Docker CLI extracts this archive on the host, utilizing the permissions of the user who executed the command.
This otherwise routine process introduces a severe security risk when the source container is under an attacker’s control. While a command like docker cp container:/report.txt ./report.txt appears secure because the user specifies the output path, CopyEscape enables an attacker to manipulate the archive generated by the running container. This manipulation allows for the insertion of a symbolic link that points outside the user-defined output directory.

During the extraction phase, the Docker CLI can then follow this malicious symlink when processing subsequent entries in the archive. This allows the attacker to redirect file writes to any location on the host’s filesystem, effectively bypassing the intended security boundary.
CopyEscape Docker Flaw
According to Imperva, the exploit chain for CopyEscape leverages a combination of two distinct weaknesses. The first is a Time-of-Check to Time-of-Use (TOCTOU) race condition during the archive generation process. This race allows a running container to convert a directory into a symbolic link while Docker is in the midst of traversing its filesystem. The outcome is an inconsistent tar archive where the same path is described as both a directory and a symlink.
The second weakness involves vulnerable extraction routines that fail to consistently restrict file writes to the designated destination folder after filesystem links have been resolved. Together, these flaws create a primitive for arbitrary file creation or overwriting, executed with the permissions of the Docker CLI process.
The implications of this vulnerability are severe. A developer executing docker cp could inadvertently have critical system files replaced, including shell startup scripts, SSH configuration files, cloud credentials, source code, or even user-level persistence files. On macOS, despite Docker Desktop running containers within a Linux virtual machine, the vulnerable extraction occurs directly on the local system, making local user files a potential target.

escape as a symlink, but its child treats it as a directory (source : imperva )The risk escalates significantly on Linux systems, particularly where administrators, Continuous Integration (CI) systems, automated pipelines, or maintenance scripts utilize sudo docker cp. Imperva demonstrated a proof-of-concept exploit where they replaced /usr/bin/runc with an attacker-controlled script. When Docker subsequently invoked the compromised runtime binary, the malicious payload executed with root privileges. It’s crucial to note that this attack doesn’t directly grant the container Docker daemon privileges; rather, it exploits the elevated authority already assigned to the docker cp command itself.
CVE-2026-17106 also extends its impact to Docker Sandboxes via the sbx cp command, posing risks for AI-agent and coding-agent workflows when retrieving files from untrusted sandboxes. Docker Sandboxes version 0.38.0 includes a fix for this specific destination-escape issue.
Docker has released patches to address this critical flaw. Docker Desktop version 4.86.0, released on August 10, 2026, contains the necessary fix. The release notes explicitly mention a destination-escape flaw within docker container cp. The underlying fix for moby/go-archive is available in version 0.3.0, meaning all earlier versions are vulnerable.
What You Should Do
- Upgrade Immediately: Update Docker Desktop to version 4.86.0 or later. Ensure Docker Engine and Docker CLI components are also updated to their respective patched releases.
- Avoid Untrusted Copies: Until all systems are fully patched, refrain from copying files from untrusted, potentially compromised, or externally-sourced containers using
docker cp. - Stop Containers Before Copying: To mitigate the live filesystem race condition, consider stopping containers before using
docker cpto retrieve files. However, always treat archives from untrusted sources as potentially hostile. - Limit Privileges: Avoid using
sudo docker cpwhenever possible. Review and remove root privileges from CI artifact-collection jobs where appropriate. - Isolate Suspicious Data: When retrieving data from suspicious containers, do so only within disposable virtual machines or isolated analysis environments to prevent host compromise.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.