<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CopyEscape on Cloudkaramchari</title><link>https://www.cloudkaramchari.com/tags/copyescape/</link><description>Recent content in CopyEscape on Cloudkaramchari</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>cloudkaramchari</copyright><lastBuildDate>Wed, 09 Sep 2026 20:33:00 +0530</lastBuildDate><atom:link href="https://www.cloudkaramchari.com/tags/copyescape/index.xml" rel="self" type="application/rss+xml"/><item><title>Docker CopyEscape (CVE-2026-17106): Fix the docker cp Host File Overwrite Vulnerability</title><link>https://www.cloudkaramchari.com/blog/docker-copyescape-cve-2026-17106-docker-cp-vulnerability-fix-guide/</link><pubDate>Wed, 09 Sep 2026 20:33:00 +0530</pubDate><guid>https://www.cloudkaramchari.com/blog/docker-copyescape-cve-2026-17106-docker-cp-vulnerability-fix-guide/</guid><description>
&lt;h1 id="docker-copyescape-cve-2026-17106-fix-the-docker-cp-host-file-overwrite-vulnerability">Docker CopyEscape (CVE-2026-17106): Fix the docker cp Host File Overwrite Vulnerability&lt;/h1>
&lt;p>If you or your CI pipeline ever run &lt;code>docker cp&lt;/code> against a container you didn't fully trust — a scanning sidecar, a customer-submitted build, an AI-agent sandbox — you need to check your Docker version right now. CVE-2026-17106, nicknamed &lt;strong>CopyEscape&lt;/strong> by the Imperva Threat Research team that found it, lets a malicious or compromised container write files anywhere on the host that the user running &lt;code>docker cp&lt;/code> can write to. On Linux, where copy operations are frequently run as root, that's a path to full host takeover.&lt;/p></description></item></channel></rss>