CVE-2018-15664: Docker

High severity, CVSS 7.5. EPSS: 3.4% chance of exploitation in the next 30 days.

In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem with root privileges, because daemon/archive.go does not do archive operations on a frozen filesystem (or from within a chroot).

Affected products

  • Docker Docker: version 17.06.0-ce only; version 17.06.1-ce only; version 17.06.2-ce only; version 17.07.0-ce only; version 17.09.0-ce only; version 17.09.1-ce only; …

Published 2019-05-23. Last modified 2026-06-17.