{"id":"CVE-2025-54287","aliases":["GHSA-w2hg-2v4p-vmh6","GO-2025-4004"],"url":"https://o3.security/vulnerability/CVE-2025-54287","summary":"Arbitrary File Read via Template Injection in Snapshot Patterns","details":"Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration \npermissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.","published":"2025-10-02T09:16:02.241Z","modified":"2026-08-12T03:51:43.524164699Z","cvss":null,"epss":{"score":0.00342,"percentile":0.26745,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/lxc/lxd","fixedVersion":"5.21.4"},{"ecosystem":"Go","name":"github.com/lxc/lxd","fixedVersion":"6.5.0"},{"ecosystem":"Go","name":"github.com/lxc/lxd","fixedVersion":"0.0.0-20250827065555-0494f5d47e41"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54287.json"},{"type":"ADVISORY","url":"https://github.com/canonical/lxd/security/advisories/GHSA-w2hg-2v4p-vmh6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54287"},{"type":"PACKAGE","url":"https://github.com/canonical/lxd"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:43.524164699Z"}}