Cross-site scripting in OPNsense - #VU139366
Published: July 26, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the victim's browser within the WebGUI origin.
The vulnerability exists due to cross-site scripting in the trust revocation CRL description handling in /ui/trust/crl when rendering a stored CRL description into the CRL edit tab label. A remote user can store a crafted CRL description to execute arbitrary script in the victim's browser within the WebGUI origin.
User interaction is required to open the CRL edit row.