| id: GO-2025-3999 |
| modules: |
| - module: github.com/canonical/lxd |
| non_go_versions: |
| - introduced: 0.0.0-20200331193331-03aab09f5b5c |
| - fixed: 0.0.0-20250827065555-0494f5d47e41 |
| - introduced: 4.0.0 |
| - fixed: 5.21.4 |
| - introduced: 6.0.0 |
| - fixed: 6.5.0 |
| summary: |- |
| Privilege Escalation via WebSocket Connection |
| Hijacking in Operations API in github.com/canonical/lxd |
| cves: |
| - CVE-2025-54289 |
| ghsas: |
| - GHSA-3g72-chj4-2228 |
| references: |
| - advisory: https://github.com/canonical/lxd/security/advisories/GHSA-3g72-chj4-2228 |
| notes: |
| - Pseudoversions specified in advisory are insufficient to accurately mark go_versions. |
| source: |
| id: GHSA-3g72-chj4-2228 |
| created: 2025-11-03T13:06:46.85112-05:00 |
| review_status: REVIEWED |