docker cp is the command everyone uses to get build artefacts, test reports or an agent's output out of a container. CopyEscape, tracked as CVE-2026-17106, turns it around: if the container you copy from is malicious, it can make the copy write files outside the destination folder on your host. With sudo docker cp on Linux, Imperva, which found the bug, says that can go as far as root code execution.
If you only copy out of containers you built from images you trust, this is a patch-when-convenient bug. If you run CI for pull requests from strangers, or let a coding agent run arbitrary code in a container and then copy its results out, it is a patch-today bug. This post is the short version: what is affected, how to check, and how to change copy-out jobs so the next bug of this kind does not hit you either.
What goes wrong
When you run docker cp container:/path ./dest, the daemon walks the container's filesystem and builds a tar archive, which is then unpacked on the host. Imperva's write-up describes a race: while the walk is in progress, a process inside the running container swaps a directory for a symlink pointing outside the destination. The walker has already classified the path as a directory, then meets the symlink, and the result is an inconsistent archive that, when extracted, writes through the symlink. The extraction side, in the moby/go-archive library, did not restrict paths tightly enough to catch it.

Two conditions matter for your defences:
- The container has to be running. The race needs a live process to do the swap. Imperva notes that stopped containers block the exploit.
- The damage is bounded by who runs the copy. Files are written with the permissions of the process doing the extraction. A copy run as root can overwrite anything.
Affected and fixed versions
Per Imperva's advisory and Docker's announcements:

- Docker Engine and CLI: fixed in 29.7.2. Earlier versions are affected.
- Docker Desktop: fixed in 4.86.0, released on 10 August 2026.
- Docker Sandboxes (the
sbx cpcommand): fixed in 0.38.0. - Wiz's vulnerability database also lists
moby/go-archivebefore 0.3.0 and Docker Compose before 5.4.0 as affected. It rates the bug CVSS v4.0 7.1 (High) and gives 18 August 2026 as the publication date.
Check your machines (2 minutes)
Engine and CLI versions come from docker version:
docker version --format 'client={{.Client.Version}} server={{.Server.Version}}'
docker compose version --short
On a Mac, the Docker Desktop version is in the app bundle (or under Settings → About):
defaults read /Applications/Docker.app/Contents/Info.plist CFBundleShortVersionString
For a fleet of CI runners, a small script that fails when the client or server is older than the fix is easier to drop into a health check:
#!/usr/bin/env bash
# copyescape-check.sh: exit 1 if Docker client or server is older than 29.7.2
set -euo pipefail
min=29.7.2
# true when $1 >= $2 (version sort)
at_least() { [ "$(printf '%s\n%s\n' "$1" "$2" | sort -V | head -n1)" = "$2" ]; }
status=0
for part in Client Server; do
v=$(docker version --format "{{.${part}.Version}}" 2>/dev/null || echo unknown)
if [ "$v" = unknown ]; then
echo "$part: unknown (daemon unreachable?)"; status=1
elif at_least "$v" "$min"; then
echo "$part: $v ok"
else
echo "$part: $v VULNERABLE (need >= $min)"; status=1
fi
done
exit $status
chmod +x copyescape-check.sh
./copyescape-check.sh
Then upgrade the usual way for each host: Docker Desktop's built-in updater, your package manager for docker-ce and docker-ce-cli on Linux, and a new runner image for hosted CI. Remember the CLI: on Linux it is a separate package from the Engine and can lag behind it.



