Stored Cross-Site Scripting in OpenWrt luci-app-https-dns-proxy
CVE-2026-67352

6.8MEDIUM

Key Information:

Vendor

Openwrt

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67352?

The luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability that affects how the resolver_url parameter is handled. This vulnerability allows authenticated users to inject malicious JavaScript into the status page viewed by administrators. When the administrator accesses the HTTPS DNS Proxy status page, the resolver URL is displayed as raw HTML, leading to the execution of arbitrary JavaScript within the browser. This exploitation can potentially compromise admin session integrity and enable further attacks, highlighting the need for timely security measures.

Affected Version(s)

luci 0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lujiefsi
.