Executive brief
OPNsense is an open-source firewall used to protect networks and route traffic. A vulnerability before version 26.1.9 allows authenticated administrators with firewall rule management privileges to inject malicious scripts into firewall rule descriptions. When other administrators view the firewall rules page, these scripts execute in their browsers, enabling attackers to steal login credentials or hijack administrative sessions.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the firewall rule description field, where unsanitized user input is persisted to the database via the filter API endpoint. The vulnerable component is the default cell formatter in opnsense_bootgrid.js, which renders rule descriptions by directly assigning raw cell content to innerHTML without sanitization. An authenticated attacker with firewall rule management privileges can embed arbitrary HTML or JavaScript payloads in the description field. When any authenticated user accesses the Firewall Rules page, the injected scripts execute in their browser context with the same privileges. The vulnerability was fixed in version 26.1.9 by adding an HTML escape function to sanitize the description output before rendering.
Affected products
- OPNsense OPNsense before 26.1.9
Timeline
- 2026-08-03: disclosed
- 26.1.9: patched: Fix applied via commit b11d6b3 adding html_safe() escaping to firewall rule description output