VYPR

luci-app-lxc

by Openwrt

Source repositories

CVEs (1)

  • CVE-2026-72842CriAug 13, 2026
    risk 0.64cvss 9.9epss

    luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape…