CVE-2025-54287

Publication date

2025-10-02 09:16:02

Family

canonical

State

PUBLISHED

Description

Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.