Template Injection Vulnerability in Canonical LXD Instance Snapshot Feature
CVE-2025-54287
7.1HIGH
What is CVE-2025-54287?
A vulnerability has been identified in the instance snapshot creation component of Canonical LXD (version 4.0 and higher), which utilizes the Pongo2 template engine. This flaw permits an attacker, granted instance configuration permissions, to leverage specially crafted snapshot pattern templates. By exploiting this vulnerability, the attacker can gain unauthorized access to arbitrary files located on the host system, posing serious security risks.
Affected Version(s)
LXD 6.0 < 6.5
LXD 5.21 < 5.21.4
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
