Information disclosure in LXD - CVE-2025-54289

 

Information disclosure in LXD - CVE-2025-54289

Published: October 21, 2025 / Updated: April 9, 2026


Vulnerability identifier: #VU117417
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54289
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the API. A remote user with read-only permissions can obtain secret values necessary for WebSocket connections via an API call and execute arbitrary commands inside instances with the victim's privileges.


Affected software

LXD
Debian Linux
incus (Debian package)

How to mitigate CVE-2025-54289

Install updates from vendor's website.

LXD - addressed in versions 5.0.5, 5.21.4, 6.5
incus (Debian package) - update to 6.0.4-2+deb13u1

External References

Related Security Bulletins