PT-2026-67336 · Openwrt · Luci-App-Adblock-Fast

·

CVE-2026-68583

·

Published

2026-08-02

·

Updated

2026-08-02

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions luci-app-adblock-fast versions prior to 1.2.4-4
Description A stored cross-site scripting issue exists in the blocklist name field, specifically involving the file url.name variable. This allows users with lower privileges to inject active HTML. The injected payload executes within the administrator's browser under the LuCI origin when the administrator accesses the AdBlock Fast status page.
Recommendations Update luci-app-adblock-fast to version 1.2.4-4 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68583

Affected Products

Luci-App-Adblock-Fast