Security: openwrt/luci
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
luci-mod-system-mountsL: ACL grants stale /etc/crontabs/root write, delegated mounts user gains root RCEGHSA-v5f9-62c7-cw29 published
Jul 21, 2026 by jow-High -
luci-app-https-dns-proxy: delegated resolver_url stored XSSGHSA-c6vf-395q-4jv6 published
Jul 17, 2026 by stangriModerate -
luci-app-adblock-fast: Stored XSS in luci-app-adblock-fast status errors from delegated blocklist namesGHSA-q335-4c83-c88h published
Jul 19, 2026 by stangriModerate -
Unchecked query traversal reads files outside the BMX7 runtime directoryGHSA-8qcq-jgrj-gvmj published
Jul 20, 2026 by jow-Moderate -
luci-app-banip: log monitor extracts first IP from log lines — attacker-controlled fields cause wrong-target blockingGHSA-r6hx-4f83-vp8m published
Jun 28, 2026 by dibdotHigh -
Command injection as root in luci-proto-openvpn generateKey (cl_meta field)GHSA-pm9w-522m-8rrh published
Jun 27, 2026 by jow-High -
luci-app-upnp: Stored XSS in luci-app-upnp, unauthenticated LAN client can inject JavaScript via UPnP port mapping descriptionGHSA-8v49-6387-7f89 published
Jun 27, 2026 by jow-High -
luci-mod-network: luci-mod-status: DHCPv6 lease hostname stored XSS in LuCI status tablesGHSA-686p-p8p9-x6fh published
Jun 27, 2026 by jow-High -
luci-app-travelmate delegated UCI write can execute travelmate auto-login command as rootGHSA-p35r-3323-6g7g published
Jun 17, 2026 by dibdotHigh -
luci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing delegated users to run commands as rootGHSA-vj96-f37g-37f6 published
Jun 16, 2026 by stangriHigh
Learn more about advisories related to openwrt/luci in the GitHub Advisory Database