#VU117417 Information disclosure in lxd - CVE-2025-54289

 

#VU117417 Information disclosure in lxd - CVE-2025-54289

Published: October 21, 2025 / Updated: April 9, 2026


Vulnerability identifier: #VU117417
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2025-54289
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
lxd
Software vendor:
Linux Containers

Description

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the API. A remote user with read-only permissions can obtain secret values necessary for WebSocket connections via an API call and execute arbitrary commands inside instances with the victim's privileges.


Remediation

Install updates from vendor's website.

External links