Cross-Site Request Forgery in LXD-UI by Canonical
CVE-2025-54286

7.5HIGH

Key Information:

Vendor

Canonical

Status
Vendor
CVE Published:
2 October 2025

What is CVE-2025-54286?

The LXD-UI interface in Canonical's LXD versions 5.0 and above is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This flaw enables an attacker to initiate and manage container instances without the user's consent by sending maliciously crafted HTML form submissions that exploit client certificate authentication processes. It underscores the importance of implementing robust security measures to safeguard against unauthorized actions in containerized environments.

Affected Version(s)

LXD 5.0 < 5.0.5

LXD 5.21 < 5.21.4

LXD 6.0 < 6.5

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54286 : Cross-Site Request Forgery in LXD-UI by Canonical