CVE-2025-54289: high-severity vulnerability in Canonical LXD
Privilege Escalation via WebSocket Connection Hijacking in LXD Operations API
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
An attacker with basic read access to LXD can take over terminal sessions through WebSocket hijacking and run commands with higher privileges. This affects LXD versions before 6.5 and is a serious security risk for shared systems.
The operations API in LXD <6.5 fails to properly validate WebSocket connection ownership, allowing an authenticated attacker with read permissions to hijack active terminal/console sessions and execute arbitrary commands with elevated privileges. The vulnerability stems from insufficient access control on WebSocket connections, enabling lateral privilege escalation in multi-user environments.
In the same product, most dangerous first.