Incus
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 12 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 25, 2025 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
No CWE data available
Most Affected Products
Recent Vulnerabilities
See more →Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root
Incus has a project restriction bypass via instance migration config override
Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution
Incus: Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`
Incus has a project restriction bypass in instance copy across projects
Incus has a project restriction bypass for custom volume copy across projects
Local Incus UI web server vulnerable to nuthentication bypass
Incus vulnerable to local privilege escalation through VM screenshot path
Incus does not verify combined fingerprint when downloading images from simplestreams servers
Incus vulnerable to local privilege escalation through custom storage volumes
Monitor Incus in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.