CVE-2025-54289
published 2025-10-02CVE-2025-54289: Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions…
PriorityP352high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.19%
9.2th percentile
Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | lxd | >= 4.0.0 < 5.21.4 | 5.21.4 |
| canonical | lxd | >= 5.21 < 5.21.4 | 5.21.4 |
| canonical | lxd | >= 6 < 6.5 | 6.5 |
| canonical | lxd | >= 6.1 < 6.5 | 6.5 |
| debian | incus | < incus 6.0.5-1 (forky) | incus 6.0.5-1 (forky) |
| debian | lxd | < incus 6.0.5-1 (forky) | incus 6.0.5-1 (forky) |
| github.com | canonical_lxd | >= 0.0.0-20200331193331-03aab09f5b5c < 0.0.0-20250827065555-0494f5d47e41 | 0.0.0-20250827065555-0494f5d47e41 |
| github.com | canonical_lxd | >= 4.0 < 5.21.4 | 5.21.4 |
| github.com | canonical_lxd | >= 6.0 < 6.5 | 6.5 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv7.4HIGH
vendor_debian7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Privilege Escalation via WebSocket Connection Hijacking in Operations API in github.com/canonical/lxd
osv·2025-11-05
CVE-2025-54289 Privilege Escalation via WebSocket Connection Hijacking in Operations API in github.com/canonical/lxd
Privilege Escalation via WebSocket Connection Hijacking in Operations API in github.com/canonical/lxd
Privilege Escalation via WebSocket Connection Hijacking in Operations API in github.com/canonical/lxd
GHSA
Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
ghsa·2025-10-02
CVE-2025-54289 [HIGH] CWE-1385 Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
### Impact
LXD's operations API includes secret values necessary for WebSocket connections when retrieving information about running operations. These secret values are used for authentication of WebSocket connections for terminal and console sessions.
Therefore, attackers with only read permissions can use secret values obtained from the operations API to hijack terminal or console sessions opened by other users. Through this hijacking, attackers can execute arbitrary commands inside instances with the victim's privileges.
### Reproduction Steps
1. Log in to LXD-UI using an account with read-only permissions
2. Open browser DevTools and execute the following JavaScript code
Note that
OSV
CVE-2025-54289: Privilege Escalation in operations API in Canonical LXD <6
osv·2025-10-02·CVSS 7.4
CVE-2025-54289 [HIGH] CVE-2025-54289: Privilege Escalation in operations API in Canonical LXD <6
Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format
OSV
Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
osv·2025-10-02
CVE-2025-54289 [HIGH] Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
### Impact
LXD's operations API includes secret values necessary for WebSocket connections when retrieving information about running operations. These secret values are used for authentication of WebSocket connections for terminal and console sessions.
Therefore, attackers with only read permissions can use secret values obtained from the operations API to hijack terminal or console sessions opened by other users. Through this hijacking, attackers can execute arbitrary commands inside instances with the victim's privileges.
### Reproduction Steps
1. Log in to LXD-UI using an account with read-only permissions
2. Open browser DevTools and execute the following JavaScript code
Note that
Debian
CVE-2025-54289: incus - Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platfor...
vendor_debian·2025·CVSS 7.4
CVE-2025-54289 [HIGH] CVE-2025-54289: incus - Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platfor...
Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format
Scope: local
forky: resolved (fixed in 6.0.5-1)
sid: resolved (fixed in 6.0.5-1)
trixie: resolved (fixed in 6.0.4-2+deb13u1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-10-02
Published