PT-2025-40335 · Canonical+2 · Lxd Lxd-Ui+2

Published

2025-10-02

·

Updated

2025-12-10

·

CVE-2025-54292

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Canonical LXD LXD-UI versions prior to 6.5 Canonical LXD LXD-UI versions prior to 5.21.4
Description A path traversal issue exists in Canonical LXD LXD-UI. Remote authenticated attackers can potentially access or modify unintended resources by using crafted resource names within URL paths.
Recommendations Update LXD-UI to version 6.5 or later. Update LXD-UI to version 5.21.4 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-54292
GHSA-7425-4QPJ-V4W3

Affected Products

Debian
Lxd Lxd-Ui
Red Os