PT-2026-20953 · Pi-Hole · Pi-Hole

T0X1Cx

·

Publicado

2026-02-19

·

Atualizado

2026-03-12

·

CVE-2026-26952

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pi-hole versions 6.4 and below
Description Pi-hole Admin Interface, a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application, is susceptible to stored HTML injection through the local DNS records configuration page. An authenticated administrator can inject code that is stored in the Pi-hole configuration and rendered when the DNS records table is viewed. The populateDataTable() function includes a data variable containing the full DNS record value, which is directly inserted into the data-tag HTML attribute without proper escaping or sanitization. An attacker can exploit this by supplying a value containing double quotes (") to prematurely close the data-tag attribute and inject additional HTML attributes. The impact is limited due to Pi-hole’s Content Security Policy (CSP) that blocks inline JavaScript.
Recommendations Update to version 6.4.1 or later.

Exploit

Correção

XSS

RCE

Improper Encoding or Escaping of Output

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-26952
GHSA-6XP4-JW73-F4QP

Produtos afetados

Pi-Hole