Template Injection Vulnerability in Canonical LXD Instance Snapshot Feature
CVE-2025-54287

7.1HIGH

Key Information:

Vendor

Canonical

Status
Vendor
CVE Published:
2 October 2025

What is CVE-2025-54287?

A vulnerability has been identified in the instance snapshot creation component of Canonical LXD (version 4.0 and higher), which utilizes the Pongo2 template engine. This flaw permits an attacker, granted instance configuration permissions, to leverage specially crafted snapshot pattern templates. By exploiting this vulnerability, the attacker can gain unauthorized access to arbitrary files located on the host system, posing serious security risks.

Affected Version(s)

LXD 6.0 < 6.5

LXD 5.21 < 5.21.4

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54287 : Template Injection Vulnerability in Canonical LXD Instance Snapshot Feature