CVE-2025-54287: Canonical Lxd
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.
Affected products
- Canonical Lxd: from 4.0.0, before 5.21.4 (fixed in 5.21.4); from 6.1, before 6.5 (fixed in 6.5)
Published 2025-10-02. Last modified 2026-06-17.