<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T02:51:59.152842+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-253953</id>
    <title>EUVD-2026-253953</title>
    <updated>2026-10-04T02:51:59.218637+00:00</updated>
    <content>EUVD-2026-253953</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-253953"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54287</id>
    <title>fkie_cve-2025-54287</title>
    <updated>2026-10-04T02:51:59.218675+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Template Injection in instance snapshot creation component in Canonical LXD (&gt;= 4.0) allows an attacker with instance configuration 
permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-54287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w2hg-2v4p-vmh6</id>
    <title>GHSA-w2hg-2v4p-vmh6 — Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns</title>
    <updated>2026-10-04T02:51:59.218709+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/lxc/lxd</p>
<p>### Impact
In LXD's instance snapshot creation functionality, the Pongo2 template engine is used in the `snapshots.pattern` configuration for generating snapshot names. While code execution functionality has not been found in this template engine, it has file reading capabilities, creating a vulnerability that allows arbitrary file reading through template injection attacks.</p>
<p>### Reproduction Steps</p>
<p>1. Log in to LXD-UI with an account that has permissions to modify instance settings
2. Set the following template injection payload in the instance snapshot pattern:</p>
<p>```
{% filter urlencode|slice:":100" %}{% include "/etc/passwd" %}{%endfilter %}
```</p>
<p>Note that the above template uses the Pongo2 template engine's include tag to read system files. It also uses urlencode and slice filters to bypass character count and type restrictions.</p>
<p>3. Set scheduled snapshots to run every minute and wait for snapshot generation
4. Wait about a minute and confirm that file contents can be obtained from the created snapshot name</p>
<p>### Risk
The attack requires having configuration change permissions for LXD instances.
The attack allows reading arbitrary files accessible with LXD process permissions. This could lead to leakage of the following information:
-​ LXD host configuration files (/etc/passwd, /etc/shadow, etc.)
-​ LXD database files (containing information about all projects and instances)
-​ Configuration files and data of other instances
-​ Sensitive information on the host system</p>
<p>###…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w2hg-2v4p-vmh6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15710-1</id>
    <title>openSUSE-SU-2025:15710-1 — govulncheck-vulndb-0.0.20251105T184115-1.1 on GA media</title>
    <updated>2026-10-04T02:51:59.218767+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20251105T184115-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15710-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-54287</id>
    <title>Withdrawn: UBUNTU-CVE-2025-54287</title>
    <updated>2026-10-04T02:51:59.218821+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: lxd, Ubuntu:Pro:18.04:LTS: lxd, Ubuntu:20.04:LTS: lxd</p>
<p>Template Injection in instance snapshot creation component in Canonical LXD (&gt;= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-54287"/>
  </entry>
</feed>
