<a id="ref-release-notes-4-0-13"></a>

# LXD 4.0.13 release notes

This is a [LTS release](https://canonical.com/lxd/docs/latest/reference/releases-snap/index.html.md#ref-releases-lts) and is recommended for production use.

This is a maintenance release for the 4.0 LTS series.

<a id="ref-release-notes-4-0-13-bugfixes"></a>

## Bug fixes

The following bug fixes are included in this release.

- [<spellexception>Instance template path traversal allows arbitrary host file write as root (CVE-2026-66897)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-q39m-8fx9-42fv)
- [<spellexception>Fix inverted conditions in NVIDIA environment variable application</spellexception>](https://github.com/canonical/lxd/commit/f38136df8a0982bb1a3e338bd8c4a7037c16849a)

<a id="ref-release-notes-4-0-13-changelog"></a>

## Change log

View the [complete list of all changes in this release](https://github.com/canonical/lxd/compare/lxd-4.0.12...lxd-4.0.13).

<a id="ref-release-notes-4-0-13-downloads"></a>

## Downloads

The source tarballs and binary clients can be found on our [download page](https://github.com/canonical/lxd/releases/tag/lxd-4.0.13).

Binary packages are also available for:

- **Linux:** `snap install lxd --channel=4.0/stable`
- **macOS client:** `brew install lxc`
- **Windows client:** `choco install lxc`
