Information disclosure in LXD - CVE-2025-54289
Published: October 21, 2025 / Updated: April 9, 2026
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the API. A remote user with read-only permissions can obtain secret values necessary for WebSocket connections via an API call and execute arbitrary commands inside instances with the victim's privileges.
Affected software
Debian Linux
incus (Debian package)
How to mitigate CVE-2025-54289
incus (Debian package) - update to 6.0.4-2+deb13u1