Cross-site scripting in OPNsense - #VU139367
Published: July 26, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the victim's browser within the WebGUI origin.
The vulnerability exists due to cross-site scripting in the firewall live view label rendering in /ui/diagnostics/firewall/log when decoding and rendering a stored firewall rule description from log-derived state. A remote user can store a crafted firewall rule description to execute arbitrary script in the victim's browser within the WebGUI origin.
User interaction is required to open the firewall live view page, and exploitation requires a packet matching the logged rule.