cbcvebase.
CVE-2025-54293
published 2025-10-02

CVE-2025-54293: Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host…

PriorityP342medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.54%
41.7th percentile
Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symbolic links.

Affected

10 ranges
VendorProductVersion rangeFixed in
canonicallxd>= 0 < 5.0.2-5+deb12u15.0.2-5+deb12u1
canonicallxd>= 0 < 5.0.2+git20231211.1364ae4-9+deb13u15.0.2+git20231211.1364ae4-9+deb13u1
canonicallxd>= 4.0.0 < 5.21.45.21.4
canonicallxd>= 5.21 < 5.21.45.21.4
canonicallxd>= 6.0 < 6.56.5
debianincus< incus 6.0.5-1 (forky)incus 6.0.5-1 (forky)
debianlxd< incus 6.0.5-1 (forky)incus 6.0.5-1 (forky)
github.comcanonical_lxd>= 0.0.0-20200331193331-03aab09f5b5c < 0.0.0-20250224180022-ec09b24179f30.0.0-20250224180022-ec09b24179f3
github.comcanonical_lxd>= 4.0 < 5.21.45.21.4
github.comcanonical_lxd>= 6.0 < 6.56.5

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv4.07.1HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv7.1HIGH
vendor_debian7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.