PT-2025-40326 · Canonical+2 · Lxd+2

Published

2025-10-02

·

Updated

2025-11-17

·

CVE-2025-54286

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Canonical LXD versions 5.0 and later
Description A Cross-Site Request Forgery (CSRF) issue exists in LXD-UI. This allows an attacker to create and start container instances without user consent by submitting crafted HTML forms that exploit client certificate authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-54286
DSA-6027-1
DSA-6028-1
GHSA-P8HW-RFJG-689H
GO-2025-4003
OPENSUSE-SU-2025:15710-1

Affected Products

Debian
Lxd
Red Os