CVE-2026-48753: Incus has an arbitrary file write via path traversal in S3 multipart upload
The S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-48753 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →