Multipass CVE Vulnerabilities
By Canonical — 2 known vulnerabilities
Critical
0
High
2
Medium
0
Low
0
None
0
All Multipass CVEs
CVE-2026-49238
8.4
high
An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment bypass vulnerability within its validate_path function in src/sshfs_mount/sftp_server.cpp. The functi
May 28, 2026
CVE-2026-49237
7.8
high
An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 updated the ownership of the multipassd daemon binary to root:wheel, five co-located binaries (multipass, qemu-img, qemu-system-aarch64, qemu-s
May 28, 2026