Privilege Escalation in operations API in Canonical LXD 6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 02 Oct 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Privilege Escalation in operations API in Canonical LXD 6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format | |
Title | Privilege Escalation via WebSocket Connection Hijacking in LXD Operations API | |
Weaknesses | CWE-1385 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2025-10-02T13:17:25.193Z
Reserved: 2025-07-18T07:59:07.917Z
Link: CVE-2025-54289

No data.

Status : Received
Published: 2025-10-02T10:15:39.053
Modified: 2025-10-02T10:15:39.053
Link: CVE-2025-54289

No data.

No data.