Cross-site scripting in OPNsense - #VU142553
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in the victim\'s browser.
The vulnerability exists due to cross-site scripting in IPsec SPD description tooltip rendering when constructing HTML attributes from stored connection or child descriptions. A remote privileged user can supply a specially crafted description value to execute arbitrary JavaScript in the victim\'s browser.
User interaction is required to hover the information icon, and exploitation additionally requires a matching runtime SPD row that maps to the stored description. The SAD renderer is described as static-equivalent but was not separately confirmed.