{"id":"CVE-2025-54289","summary":"Privilege Escalation via WebSocket Connection Hijacking in LXD Operations API","details":"Privilege Escalation in operations API in Canonical LXD \u003c6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format","aliases":["GHSA-3g72-chj4-2228","GO-2025-3999"],"modified":"2026-08-12T03:51:49.201499529Z","published":"2025-10-02T09:23:03.238Z","related":["openSUSE-SU-2025:15710-1","openSUSE-SU-2026:21483-1"],"database_specific":{"cna_assigner":"canonical","cwe_ids":["CWE-1385"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54289.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54289.json"},{"type":"ADVISORY","url":"https://github.com/canonical/lxd/security/advisories/GHSA-3g72-chj4-2228"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54289"},{"type":"PACKAGE","url":"https://github.com/canonical/lxd"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/canonical/lxd","events":[{"introduced":"03aab09f5b5cbdada00c6539877dcf5932fcde98"},{"fixed":"0494f5d47e41af69a8374568c0cb8b3eefd72a6a"},{"introduced":"5a492a3f0036c44d22c344505952e06ce517993a"},{"fixed":"fec3cc832ca782d398c82d38f8532ef9d5be2e00"}],"database_specific":{"cpe":"cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.0.0"},{"fixed":"5.21.4"},{"introduced":"6.1"},{"fixed":"6.5"}],"source":"CPE_RANGE"}}],"versions":["lxd-5.17","lxd-5.16","lxd-5.15","lxd-5.14","lxd-5.13","lxd-5.12","lxd-5.11","lxd-5.10","lxd-5.9","lxd-5.8","lxd-5.7","lxd-5.6","lxd-5.5","lxd-5.4","lxd-5.3","lxd-5.2","lxd-5.1","lxd-5.0.0","lxd-4.24","lxd-4.23","lxd-4.22","lxd-4.21","lxd-4.20","lxd-4.19","lxd-4.18","lxd-4.17","lxd-4.16","lxd-4.15","lxd-4.14","lxd-4.13","lxd-4.12","lxd-4.11","lxd-4.10","lxd-4.9","lxd-4.8","lxd-4.7","lxd-4.6","lxd-4.5","lxd-4.4","lxd-4.3","lxd-4.2","lxd-4.1","lxd-4.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54289.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}