blob: 141f8f536a4a3ea09e6484cfd5d080a4e7f89f87 [file] [edit]
{
"schema_version": "1.3.1",
"id": "GO-2025-4004",
"modified": "0001-01-01T00:00:00Z",
"published": "0001-01-01T00:00:00Z",
"aliases": [
"CVE-2025-54287",
"GHSA-w2hg-2v4p-vmh6"
],
"summary": "Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns in github.com/lxc/lxd",
"details": "Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns in github.com/lxc/lxd",
"affected": [
{
"package": {
"name": "github.com/lxc/lxd",
"ecosystem": "Go"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
],
"ecosystem_specific": {
"custom_ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "5.21.4"
},
{
"introduced": "4.0.0"
},
{
"introduced": "0.0.0-20200331193331-03aab09f5b5c"
},
{
"fixed": "0.0.0-20250827065555-0494f5d47e41"
}
]
}
]
}
},
{
"package": {
"name": "github.com/lxc/lxd/v6",
"ecosystem": "Go"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
],
"ecosystem_specific": {
"custom_ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "6.0.0"
},
{
"fixed": "6.5.0"
}
]
}
]
}
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-w2hg-2v4p-vmh6"
}
],
"database_specific": {
"url": "https://pkg.go.dev/vuln/GO-2025-4004",
"review_status": "REVIEWED"
}
}