CVE-2025-54287 - Arbitrary File Read via Template Injection in Snapshot Patterns
CVE ID : CVE-2025-54287
Published : Oct. 2, 2025, 10:15 a.m. | 47 minutes ago
Description : Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 2, 2025, 10:15 a.m. | 47 minutes ago
Description : Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...