cbcvebase.
CVE-2025-54287
published 2025-10-02

CVE-2025-54287: Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read…

high7.1CVSS 4.0
AVNACLATNPRLUINVCHVINVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.

Affected

11 ranges
VendorProductVersion rangeFixed in
canonicallxd>= 0 < 5.0.2-5+deb12u15.0.2-5+deb12u1
canonicallxd>= 0 < 5.0.2+git20231211.1364ae4-9+deb13u15.0.2+git20231211.1364ae4-9+deb13u1
canonicallxd>= 4.0.0 < 5.21.45.21.4
canonicallxd>= 5.21 < 5.21.45.21.4
canonicallxd>= 6.0 < 6.56.5
canonicallxd>= 6.1 < 6.56.5
debianincus< incus 6.0.5-1 (forky)incus 6.0.5-1 (forky)
debianlxd< incus 6.0.5-1 (forky)incus 6.0.5-1 (forky)
github.comlxc_lxd>= 0.0.0-20200331193331-03aab09f5b5c < 0.0.0-20250827065555-0494f5d47e410.0.0-20250827065555-0494f5d47e41
github.comlxc_lxd>= 4.0.0 < 5.21.45.21.4
github.comlxc_lxd>= 6.0.0 < 6.5.06.5.0

CVSS provenance

nvdv4.07.1HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv7.1HIGH