PT-2026-30628 · Pi-Hole · Pi-Hole Admin Interface

·

CVE-2026-33406

·

Published

2026-04-06

·

Updated

2026-04-06

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pi-hole Admin Interface versions 6.0 through 6.4
Description Configuration values from the '/api/config' endpoint are inserted into HTML value attributes without proper escaping in settings-advanced.js, allowing HTML attribute injection. A double quote in a configuration value allows an attacker to break out of the attribute context. While the server's Content Security Policy (CSP)—a security layer that helps detect and mitigate certain types of attacks, including Cross-Site Scripting (XSS)—prevents JavaScript execution, injected attributes can be used for UI redressing by altering element styling. The main attack vector involves importing a malicious teleporter backup, which bypasses server-side validation for individual fields.
Recommendations Update Pi-hole Admin Interface to version 6.5.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33406
GHSA-9RFM-C5G6-538P

Affected Products

Pi-Hole Admin Interface