CVE-2025-54287: Arbitrary File Read via Template Injection in Snapshot Patterns

Published Oct 2, 2025
·
Updated

Impact In LXD's instance snapshot creation functionality, the Pongo2 template engine is used in the snapshots.pattern configuration for generating snapshot names. While code execution functionality has not been found in this template engine, it has file reading capabilities, creating a vulnerability that allows arbitrary file reading through template injection attacks.

Reproduction Steps

1. Log in to LXD-UI with an account that has permissions to modify instance settings 2. Set the following template injection payload in the instance snapshot pattern:

{% filter urlencode|slice:":100" %}{% include "/etc/passwd" %}{%endfilter %}

Note that the above template uses the Pongo2 template engine's include tag to read system files. It also uses urlencode and slice filters to bypass character count and type restrictions.

3. Set scheduled snapshots to run every minute and wait for snapshot generation 4. Wait about a minute and confirm that file contents can be obtained from the created snapshot name

Risk The attack requires having configuration change permissions for LXD instances. The attack allows reading arbitrary files accessible with LXD process permissions. This could lead to leakage of the following information: -​ LXD host configuration files (/etc/passwd, /etc/shadow, etc.) -​ LXD database files (containing information about all projects and instances) -​ Configuration files and data of other instances -​ Sensitive information on the host system

Countermeasures Pongo2 provides mechanisms for sandboxing templates.

Template sandboxing (directory patterns, banned tags/filters) ( https://github.com/flosch/pongo2/tree/master?tab=readme-ov-file#features )

This functionality allows banning specific tags and filters by generating a custom TemplateSet.

At minimum, the following tags are considered to pose a risk of file leakage on the LXD host when used. Therefore, banning these can provide countermeasures against file reading attacks. -​ include -​ ssi -​ extends -​ import

The deny-list approach is prone to vulnerability recurrence due to missed countermeasures or new feature additions. Therefore, as the safest approach, we recommend using an allow-list format to permit only necessary functions.

However, as far as our investigation shows, pongo2 does not have functionality to retrieve a list of registered tags or filters, nor does it provide means to implement an allow-list approach. Therefore, it is necessary to either forcibly obtain the registration list through reflection and ban anything not on the allow-list, or ban everything from the current implemented list since the library has not been updated for about two years.

In LXD's implementation, template injection attacks can be prevented by modifying the RenderTemplate function in shared/util.go to use a restricted TemplateSet as shown above.

Patches

| LXD Series | Status | | ------------- | ------------- | | 6 | Fixed in LXD 6.5 | | 5.21 | Fixed in LXD 5.21.4 | | 5.0 | Ignored - Not critical | | 4.0 | Ignored - EOL and not critical |

References Reported by GMO Flatt Security Inc.

Other sources

Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.

MITRE

Affected Software

7 affected componentsFixes available
Canonical LXD>=4.0
go/github.com/lxc/lxd>=0.0.0-20200331193331-03aab09f5b5c<0.0.0-20250827065555-0494f5d47e41
0.0.0-20250827065555-0494f5d47e41
go/github.com/lxc/lxd>=6.0<6.5
6.5
go/github.com/lxc/lxd>=4.0<5.21.4
5.21.4
All of the following
Any of the following
Canonical LXD>=4.0.0<5.21.4
Canonical LXD>=6.1<6.5
Linux Linux kernel

Event History

Oct 2, 2025
CVE Published
via MITRE·09:16 AM
Data Sourced
via MITRE·09:16 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
Affected Software
Advisory Published
via GitHub·09:21 PM
Data Sourced
via GitHub·09:21 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-54287?

CVE-2025-54287 is considered a high severity vulnerability due to its potential for unauthorized file access on the host system.

2

How do I fix CVE-2025-54287?

To mitigate CVE-2025-54287, it is recommended to upgrade Canonical LXD to the latest version that addresses this vulnerability.

3

What is affected by CVE-2025-54287?

CVE-2025-54287 affects Canonical LXD versions 4.0 and above that allow instance configuration permissions.

4

What type of exploitation is possible with CVE-2025-54287?

CVE-2025-54287 can be exploited by attackers to read arbitrary files on the host system through malicious snapshot pattern templates.

5

Who is at risk from CVE-2025-54287?

Users and administrators of Canonical LXD versions 4.0 and higher with instance configuration permissions are at risk from CVE-2025-54287.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203