CVE-2025-54287: Canonical Lxd

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.

Affected products

  • Canonical Lxd: from 4.0.0, before 5.21.4 (fixed in 5.21.4); from 6.1, before 6.5 (fixed in 6.5)

Published 2025-10-02. Last modified 2026-06-17.