CVE-2025-54289

Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-10-02 10:15

Updated : 2025-10-24 14:34


NVD link : CVE-2025-54289

Mitre link : CVE-2025-54289

CVE.ORG link : CVE-2025-54289


JSON object : View

Products Affected

canonical

  • lxd
CWE
CWE-1385

Missing Origin Validation in WebSockets