CVE-2025-54292

MEDIUM

Canonical Lxd < 5.21.4 - Path Traversal

Title source: rule

Description

Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attackers to access or modify unintended resources via crafted resource names embedded in URL paths.

Scores

CVSS v3 4.6
EPSS 0.0003
EPSS Percentile 9.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Classification

CWE
CWE-22
Status published

Affected Products (1)

canonical/lxd < 5.21.4

Timeline

Published Oct 02, 2025
Tracked Since Feb 18, 2026