VYPR
High severityNVD Advisory· Published Oct 2, 2025· Updated Feb 26, 2026

CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI

CVE-2025-54286

Description

Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/canonical/lxdGo
>= 5.0, < 5.0.55.0.5
github.com/canonical/lxdGo
>= 5.1, < 5.21.45.21.4
github.com/canonical/lxdGo
>= 6.0, < 6.56.5
github.com/canonical/lxdGo
>= 0.0.0-20220401034332-1e1349e3cbf3, < 0.0.0-20250827065555-0494f5d47e410.0.0-20250827065555-0494f5d47e41

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.