Executive brief
wg-easy is a web-based administration interface for WireGuard VPN services. Users with client creation permissions can inject arbitrary commands into the VPN configuration by crafting malicious client names, leading to root-level code execution on the server. This allows complete compromise of the VPN infrastructure and the underlying host system.
Technical details
An OS command injection vulnerability exists in wg-easy 15.3.0 where user-supplied client names are written directly into WireGuard configuration files without sanitizing newline characters. An attacker with the clients.create permission can inject newline-delimited WireGuard PostUp directives into the client name field. When wg-quick processes the configuration file, these injected directives are executed with root privileges, allowing arbitrary command execution. The vulnerability requires valid credentials with client creation permissions but results in complete system compromise through root code execution.
Affected products
- wg-easy wg-easy 15.3.0
Timeline
- 2026-08-11: disclosed