Vulnerability Report: GO-2025-4004
- CVE-2025-54287, GHSA-w2hg-2v4p-vmh6
- Affects: github.com/lxc/lxd, github.com/lxc/lxd/v6
- Published: Nov 05, 2025
Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns in github.com/lxc/lxd
For detailed information about this vulnerability, visit https://github.com/canonical/lxd/security/advisories/GHSA-w2hg-2v4p-vmh6.
Affected Modules
-
PathGo VersionsCustom Versions*
-
all versions, no known fixedbefore 5.21.4, from 0.0.0-20200331193331-03aab09f5b5c before 0.0.0-20250827065555-0494f5d47e41
-
all versions, no known fixedfrom 6.0.0 before 6.5.0
*Custom versions, which can't be mapped automatically to standard Go module versions, are ignored by govulncheck. (See this note on versions for more details.)
Aliases
References
- https://github.com/canonical/lxd/security/advisories/GHSA-w2hg-2v4p-vmh6
- https://vuln.go.dev/ID/GO-2025-4004.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.