Cross-site scripting in OPNsense - #VU142554
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in the victim\'s browser.
The vulnerability exists due to cross-site scripting in Traffic Shaper relation description tooltip rendering in Firewall Rules when constructing HTML attributes from stored shaper descriptions. A remote privileged user can modify a referenced shaper object\'s description with a specially crafted value to execute arbitrary JavaScript in the victim\'s browser.
User interaction is required to hover the gear icon, and exploitation additionally requires that a firewall rule already reference the affected pipe or queue.