CopyEscape Docker Flaw Allows Malicious Containers to Overwrite Host Files
A critical vulnerability, CVE-2026-17106 (CopyEscape), in Docker's archive handling allows malicious containers to overwrite host files and potentially gain root access.

A critical vulnerability, dubbed CopyEscape (CVE-2026-17106), has been discovered in Docker's archive extraction process, enabling malicious containers to overwrite arbitrary host files and potentially achieve root-level compromise. The flaw resides within the moby/go-archive library, which Docker uses to handle file transfers between containers and the host system.
When a user executes a docker cp command to copy files from a container to their host, Docker doesn't perform a direct transfer. Instead, it first packages the requested files from the container into a tar archive. This archive is then sent to the local Docker CLI, which extracts it using the file permissions of the user who initiated the command. This process becomes a significant security risk when the source container is controlled by an attacker.
The CopyEscape vulnerability exploits a race condition during the archive generation process. An attacker-controlled container can manipulate the filesystem, changing a directory into a symbolic link while Docker is still processing it. This creates an inconsistent tar archive where a path is recognized as both a directory and a symlink. Subsequent extraction routines fail to properly validate these symlinks, allowing the Docker CLI to follow them and write files outside the intended destination directory.
This arbitrary file write primitive can be leveraged to replace critical system files or user-specific configurations. For instance, a developer running docker cp might have their shell startup files, SSH configurations, cloud credentials, or source code overwritten. In a proof-of-concept, researchers demonstrated replacing the /usr/bin/runc binary with a malicious script, leading to arbitrary code execution with root privileges when Docker subsequently invoked the compromised runtime.
The impact varies across operating systems. On macOS, the vulnerable extraction process occurs locally, making user files susceptible even though containers run within a Linux VM. The risk is amplified on Linux systems where sudo docker cp is frequently used by administrators, CI/CD pipelines, or automated scripts, granting attackers elevated privileges.
This vulnerability also affects Docker Sandboxes, specifically through the sbx cp command, posing a risk to AI and coding agent workflows that retrieve files from untrusted sandbox environments. Docker Sandboxes version 0.38.0 has been patched to address this destination-escape issue.
Docker has addressed CVE-2026-17106 in Docker Desktop version 4.86.0, released on August 10, 2026. The underlying fix for the moby/go-archive library is available in version 0.3.0. Organizations are strongly advised to upgrade Docker Desktop to the latest patched version and ensure their Docker Engine and CLI are also updated. Until upgrades are complete, users should exercise extreme caution when copying files from untrusted or compromised containers, avoid using sudo docker cp, and consider stopping containers before copying files to mitigate the race condition exploit.
CopyEscape highlights that even routine operations like archive extraction can become attack vectors. It underscores the importance of robust security boundaries, especially in containerized environments where the interaction between containers and the host system must be meticulously secured.