Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication.
2025-10-02T10:15:38.427
2025-10-22T15:47:31.957
Analyzed
CVSSv3.1: 8.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | canonical | lxd | < 5.0.5 | Yes |
| Application | canonical | lxd | < 5.21.4 | Yes |
| Application | canonical | lxd | < 6.5 | Yes |
| Operating System | linux | linux_kernel | - | No |