CVE-2026-68583

luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the administrator's browser under the LuCI origin.
Configurations

No configuration.

History

03 Aug 2026, 17:16

Type Values Removed Values Added
References () https://github.com/openwrt/luci/security/advisories/GHSA-q335-4c83-c88h - () https://github.com/openwrt/luci/security/advisories/GHSA-q335-4c83-c88h -

02 Aug 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-08-02 13:16

Updated : 2026-08-03 17:16


NVD link : CVE-2026-68583

Mitre link : CVE-2026-68583

CVE.ORG link : CVE-2026-68583


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')