Security: openwrt/luci
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
luci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing delegated users to run commands as rootGHSA-vj96-f37g-37f6 published
Jun 16, 2026 by stangriHigh -
luci-proto-openvpn read ACL exposes generateKey, allowing delegated users to execute commands as rootGHSA-vrj9-6xwg-6cf9 published
Jun 27, 2026 by jow-High -
luci-app-dockerman read ACL exposes ttyd_start, allowing delegated users to execute commands as rootGHSA-cq4h-h8jr-3xqv published
Jul 20, 2026 by jow-High -
luci-app-samba4 read ACL allows authenticated root command execution via smbd file.execGHSA-vx64-mmp7-h36c published
Jun 27, 2026 by jow-High -
`luci-app-tailscale-community` allows delegated LuCI users to execute commands as root through `tailscale.do_login`GHSA-xwc5-mx58-rh35 published
Jun 11, 2026 by jow-Critical -
luci-app-adblock-fast:Delegated `luci-app-adblock-fast` users can reach root command execution by injecting newline-separated cron entriesGHSA-ggpf-xrph-wg5v published
Jun 15, 2026 by stangriHigh -
Path Traversal in luci-app-openvpn Leading to Root Code Execution and PersistenceGHSA-jjcx-c284-2qv8 published
Jul 21, 2026 by jow-Critical -
luci-app-lxc ACL inconsistency allows a low-privileged LuCI user to gain OpenWrt host rootGHSA-jf59-v86x-fwf2 published
Jul 21, 2026 by dibdotCritical -
luci-mod-network: Possible XSS attack in WiFi scan on Joining Wireless Client modalGHSA-vvj6-7362-pjrw published
Mar 18, 2026 by AnsuelHigh
Learn more about advisories related to openwrt/luci in the GitHub Advisory Database