CVE-2025-54292
MEDIUMCanonical Lxd < 5.21.4 - Path Traversal
Title source: ruleDescription
Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attackers to access or modify unintended resources via crafted resource names embedded in URL paths.
Scores
CVSS v3
4.6
EPSS
0.0003
EPSS Percentile
9.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Classification
CWE
CWE-22
Status
published
Affected Products (1)
canonical/lxd
< 5.21.4
Timeline
Published
Oct 02, 2025
Tracked Since
Feb 18, 2026