OpenWrt LuCI Container App ACL Bypass Leads to Root RCE
luci-app-lxc ACL inconsistency lets low-privileged authenticated users exploit path traversal to achieve root code execution on the OpenWrt host. CVSS 9.9 critical.
- Vendor
- OpenWrt
- Product
- LuCI (luci-app-lxc)
- CVSS
- 9.9
- EPSS (exploit probability)
- 0.4%
- Status
- patched
- Published
luci-app-lxc in OpenWrt’s LuCI web interface contains an access control inconsistency. Low-privileged authenticated LuCI users can access backend container management routes without proper authorization checks. The lxc_name parameter is vulnerable to path traversal via /.%2E sequences, allowing an attacker to escape container directories and control host-side scripts executed through lxc.hook.start-host. Those hook scripts run as root on the OpenWrt host.
Affected: OpenWrt installations running luci-app-lxc
Patch: Fix tracked in the upstream OpenWrt LuCI repository. Remove luci-app-lxc if not in use.
Source: GHSA-jf59-v86x-fwf2
