7.1
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration
permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.
permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.
Basic Information
ID
CVE-2025-54287
Source
canonical
Published
Oct 2, 2025 at 09:16
Affected Product
Vendor
Canonical
Product
LXD
Version
6.0
Affected Versions
Canonical LXD 6.0
Canonical LXD 5.21
Canonical LXD 5.21