CVE-2025-54292

Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attackers to access or modify unintended resources via crafted resource names embedded in URL paths.
CVSS

No CVSS.

Configurations

No configuration.

History

02 Oct 2025, 16:15

Type Values Removed Values Added
References () https://github.com/canonical/lxd/security/advisories/GHSA-7425-4qpj-v4w3 - () https://github.com/canonical/lxd/security/advisories/GHSA-7425-4qpj-v4w3 -

02 Oct 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-02 10:15

Updated : 2025-10-02 19:11


NVD link : CVE-2025-54292

Mitre link : CVE-2025-54292

CVE.ORG link : CVE-2025-54292


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')