Docker has been found to contain a critical security flaw—CVE-2026-17106, dubbed “CopyEscape”—that allows malicious containers to write files somewhere on the host system outside of the intended destination, even reaching root-level access. The issue arises in how Docker handles archived files during docker cp commands, specifically in the archive extraction mechanisms of the moby/go-archive package.
What CopyEscape Is and How It Works
When a user invokes docker cp to transfer files from a container to a host, Docker first bundles the content into a tar archive. The local Docker CLI then extracts this archive under the privileges of the user executing the command. In a scenario where the container is under attacker control, this becomes a dangerous pathway.
The vulnerability allows an attacker to manipulate the archived tar such that a symlink is introduced, pointing outside of the target extraction directory. During extraction, the Docker CLI follows this symlink and ends up writing files into unexpected locations on the host. This could include overwriting user startup scripts, SSH config files, cloud credential files, or even system binaries.
Deep Dive into the Exploit Mechanics
The flaw is actually a two-phase hit. First is a time-of-check to time-of-use (TOCTOU) race condition while Docker builds the archive: a container changes a directory into a symlink during the filesystem walk. That creates a mismatch—the tar archive sees the same path as both a directory and a symlink. Second, the extraction process fails to securely confine file writes after resolving symlinks, meaning that files intended for a given folder can actually land elsewhere on the host.
On macOS, even though Docker Desktop runs containers inside a Linux virtual machine, the vulnerable extraction happens on the local file system—exposing sensitive user files. On Linux, the threat is elevated when administrators or automation tools invoke docker cp with root or sudo permissions. A proof-of-concept showed replacing /usr/bin/runc with a malicious script, which later executes with root privileges when Docker invokes that binary.
What’s Affected, What’s Fixed
CVE-2026-17106 applies across Docker Desktop (any platform), Docker Engine, Docker CLI, and even Docker Sandboxes via sbx cp. The issue was corrected in Docker Desktop version 4.86.0, released August 10, 2026. The moby/go-archive package was updated to version 0.3.0; earlier versions remain vulnerable. Docker Sandboxes version 0.38.0 includes the fix for destination-escape exploits.
Mitigation Strategies Until Patch Deployment
Users are strongly urged to upgrade Docker components to the fixed versions immediately. In the meantime, avoid using docker cp on active containers if those containers are untrusted or processing external content. One safer route is to stop the container before copying files, which disarms the live filesystem race needed for the attack.
Additionally, reduce reliance on sudo docker cp, especially within CI or artifact-collection workflows. Remove unnecessary root privileges, and when analyzing data from untrusted containers, do so in disposable VMs or isolated environments.
CopyEscape demonstrates that even seemingly benign operations—like copying files from a container—represent serious security boundaries. What might be viewed as routine file management can constitute an attack vector allowing a malicious container to break out and gain control of host files.
Analytically, this vulnerability underscores how containerization isn’t automatically equal to containment. The gap between a container’s filesystem and the host’s can be breached if standard tools (like docker cp) mismanage archive paths and filesystem semantics. Moving forward, organizations will need to scrutinize not just which container runtime they use, but how common utilities and file transfer operations prevent destination escapes. The broader lesson: security must be baked into every layer—including convenience commands that are often overlooked.