CVE-2025-54286

Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication.
CVSS

No CVSS.

Configurations

No configuration.

History

02 Oct 2025, 14:15

Type Values Removed Values Added
References () https://github.com/canonical/lxd/security/advisories/GHSA-p8hw-rfjg-689h - () https://github.com/canonical/lxd/security/advisories/GHSA-p8hw-rfjg-689h -

02 Oct 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-02 10:15

Updated : 2025-10-02 19:11


NVD link : CVE-2025-54286

Mitre link : CVE-2025-54286

CVE.ORG link : CVE-2025-54286


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)