{"id":"CVE-2025-54289","details":"Privilege Escalation in operations API in Canonical LXD \u003c6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format","aliases":["GHSA-3g72-chj4-2228","GO-2025-3999"],"modified":"2026-04-10T05:29:30.867260Z","published":"2025-10-02T10:15:39.053Z","related":["GHSA-3g72-chj4-2228","openSUSE-SU-2025:15710-1"],"references":[{"type":"EVIDENCE","url":"https://github.com/canonical/lxd/security/advisories/GHSA-3g72-chj4-2228"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/canonical/lxd","events":[{"introduced":"03aab09f5b5cbdada00c6539877dcf5932fcde98"},{"fixed":"0494f5d47e41af69a8374568c0cb8b3eefd72a6a"},{"introduced":"5a492a3f0036c44d22c344505952e06ce517993a"},{"fixed":"fec3cc832ca782d398c82d38f8532ef9d5be2e00"}],"database_specific":{"versions":[{"introduced":"4.0.0"},{"fixed":"5.21.4"},{"introduced":"6.1"},{"fixed":"6.5"}]}}],"versions":["lxd-4.0.0","lxd-4.1","lxd-4.10","lxd-4.11","lxd-4.12","lxd-4.13","lxd-4.14","lxd-4.15","lxd-4.16","lxd-4.17","lxd-4.18","lxd-4.19","lxd-4.2","lxd-4.20","lxd-4.21","lxd-4.22","lxd-4.23","lxd-4.24","lxd-4.3","lxd-4.4","lxd-4.5","lxd-4.6","lxd-4.7","lxd-4.8","lxd-4.9","lxd-5.0.0","lxd-5.1","lxd-5.10","lxd-5.11","lxd-5.12","lxd-5.13","lxd-5.14","lxd-5.15","lxd-5.16","lxd-5.17","lxd-5.2","lxd-5.3","lxd-5.4","lxd-5.5","lxd-5.6","lxd-5.7","lxd-5.8","lxd-5.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54289.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}