PT-2025-40326 · Canonical+2 · Lxd+2

CVE-2025-54286

·

Published

2025-10-02

·

Updated

2026-07-30

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Canonical LXD versions 5.0 and later
Description A Cross-Site Request Forgery (CSRF) issue exists in LXD-UI. This allows an attacker to create and start container instances without user consent by submitting crafted HTML forms that exploit client certificate authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-54286
DSA-6027-1
DSA-6028-1
GHSA-P8HW-RFJG-689H
GO-2025-4003
OPENSUSE-SU-2025:15710-1
OPENSUSE-SU-2026:21483-1

Affected Products

Debian
Lxd
Red Os