Cross-site scripting in OPNsense - #VU139369
Published: July 26, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the victim's browser within the WebGUI origin.
The vulnerability exists due to cross-site scripting in the IDS rule details view when rendering Suricata rule reference:url metadata as HTML. A remote user can control a trusted or enabled ruleset source to execute arbitrary script in the victim's browser within the WebGUI origin.
User interaction is required to open the installed rule details dialog.