Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.
| Software | From | Fixed in |
|---|---|---|
github.com/lxc/lxd
|
4.0 | 5.21.4 |
github.com/lxc/lxd
|
6.0 | 6.5 |
github.com/lxc/lxd
|
0.0.0-20200331193331-03aab09f5b5c | 0.0.0-20250827065555-0494f5d47e41 |
| canonical / lxd | 4.0.0 | 5.21.4 |
| canonical / lxd | 6.1 | 6.5 |