Path Traversal Vulnerability in Canonical LXD-UI
CVE-2025-54292

4.8MEDIUM

Key Information:

Vendor

Canonical

Status
Vendor
CVE Published:
2 October 2025

What is CVE-2025-54292?

The vulnerability in Canonical's LXD-UI prior to version 6.5 and 5.21.4 allows remote authenticated attackers to exploit a path traversal flaw. By crafting specific resource names in URL paths, attackers may gain unauthorized access to sensitive resources, potentially leading to data exposure and modification of unintended files on the system.

Affected Version(s)

LXD 6.0 < 6.5

LXD 5.21 < 5.21.4

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54292 : Path Traversal Vulnerability in Canonical LXD-UI