Path traversal in LXD - CVE-2025-54292

 

Path traversal in LXD - CVE-2025-54292

Published: April 9, 2026


Vulnerability identifier: #VU125580
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54292
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper input validation in URL path construction in lxd-ui when embedding user-controlled resource names in URL paths. A remote user can create a malicious resource name containing path traversal sequences to disclose sensitive information.

User interaction is required, and exploitation occurs when another user performs operations on the crafted resource, causing path normalization to switch to a different project or resource.


Affected software

LXD

How to mitigate CVE-2025-54292

Install security update from vendor's website.

LXD - update to 0.18

External References

Related Security Bulletins