Cross-site scripting in OPNsense - #VU139368
Published: July 26, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the victim's browser within the WebGUI origin.
The vulnerability exists due to cross-site scripting in the dashboard announcements widget when rendering feed-supplied description and link data into HTML. A remote user can control a trusted RSS feed source to execute arbitrary script in the victim's browser within the WebGUI origin.
User interaction is required to open the dashboard with the Announcements widget enabled.