CVE-2025-54286: Canonical Lxd
High severity, CVSS 8.8. EPSS: 0.1% chance of exploitation in the next 30 days.
Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication.
Affected products
- Canonical Lxd: from 5.0.0, before 5.0.5 (fixed in 5.0.5); from 5.21.0, before 5.21.4 (fixed in 5.21.4); from 6.1, before 6.5 (fixed in 6.5)
Published 2025-10-02. Last modified 2026-06-17.