CVE-2026-1386

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
23/01/2026
Last modified:
30/01/2026

Description

A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the jailer is executed with root privileges. <br /> <br /> To mitigate this issue, users should upgrade to version v1.13.2 or 1.14.1 or above.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:amazon:firecracker:*:*:*:*:*:*:*:* 1.13.2 (excluding)
cpe:2.3:a:amazon:firecracker:1.14.0:-:*:*:*:*:*:*
cpe:2.3:a:amazon:firecracker:1.14.0:dev:*:*:*:*:*:*