Critical 'CopyEscape' Vulnerability in Docker's `docker cp` Command Exposes Hosts to Root Compromise
A critical security vulnerability, identified as CVE-2026-17106 and nicknamed 'CopyEscape,' has been discovered in Docker's `docker cp` command. This flaw allows a malicious container to escape its boundaries and write files to arbitrary locations on the host filesystem, potentially leading to remote code execution and full system compromise. The issue stems from how Docker handles archive extraction during the `docker cp` operation. Instead of a direct file transfer, the Docker daemon first packages the requested files from the container into a tar archive. The local Docker CLI then extracts this archive using the permissions of the user who initiated the command. Attackers can exploit this by manipulating the archive created by a running container, planting a symlink that points outside the chosen output directory. When the Docker CLI extracts subsequent entries from the archive, it follows this malicious symlink, causing files to be written to unintended locations on the host.
This vulnerability is highly significant for practitioners because it directly undermines the security model of containerization. The core promise of containers is process isolation, preventing code running inside a container from affecting the host system or other containers. 'CopyEscape' shatters this promise, allowing a compromised or malicious container to gain significant control over the host. This is particularly concerning in CI/CD pipelines, development environments, and any scenario where users might copy files from untrusted or potentially compromised containers. The ability to achieve root-level compromise means an attacker could install backdoors, steal sensitive data, or pivot to other systems within the network.
The discovery of 'CopyEscape' fits into a broader, well-established trend of container escape vulnerabilities that periodically emerge, challenging the security assumptions of containerized environments. Similar vulnerabilities, such as the 'Leaky Vessels' flaws in `runc` and BuildKit discovered in early 2024, have previously demonstrated that the isolation provided by container runtimes is not absolute and requires continuous scrutiny and patching. These incidents underscore the complexity of securing the entire container supply chain, from base images to runtime operations. The increasing adoption of containers for sensitive workloads, including AI agent workflows as highlighted by Docker's recent focus on Sandboxes, makes such vulnerabilities even more impactful.
In practice, practitioners must prioritize immediate action. Docker has addressed this flaw in Docker Desktop 4.86.0 and later, and the underlying `moby/go-archive` fix is available in version 0.3.0. Organizations should upgrade Docker Desktop to version 4.86.0 or newer, and update Docker Engine and Docker CLI to their respective patched releases. Until upgrades are complete, administrators should strictly avoid using `docker cp` to copy files from untrusted, compromised, or externally-sourced containers. A temporary mitigation involves stopping a container before using `docker cp`, as this can prevent the live filesystem race condition exploited by 'CopyEscape'. However, the long-term solution is to ensure all Docker components are up-to-date and to treat all archives from untrusted sources as potentially hostile.
Read original source