CVE 7.4 HIGH

Privilege Escalation via WebSocket Connection Hijacking in LXD Operations API_CVE-2025-54289

7.4 / 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

Privilege Escalation in operations API in Canonical LXD 6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format

Basic Information

ID CVE-2025-54289
Source canonical
Published Oct 2, 2025 at 09:23

Affected Product

Vendor Canonical
Product LXD
Version 6
Affected Versions Canonical LXD 6
Canonical LXD 5.21

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.