Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/canonical/lxd(Go) | 5.0 | 5.0.5 | N/A |
| github.com/canonical/lxd(Go) | 5.1 | 5.21.4 | N/A |
| github.com/canonical/lxd(Go) | 6.0 | 6.5 | N/A |
| github.com/canonical/lxd(Go) | 0.0.0-20220401034332-1e1349e3cbf3 | 0.0.0-20250827065555-0494f5d47e41 | N/A |
CVSS Metrics