Skip to content
Critical Vulnerabilities in Pi-hole Allow Arbitrary Code Execution

Critical Vulnerabilities in Pi-hole Allow Arbitrary Code Execution

First seen 21 Sep 2026, 14:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 21, 2026 at 18:54 UTC
  • Multiple vulnerabilities in Pi-hole allow arbitrary code execution via configuration imports.
  • Affected versions include all releases from FTL 6.0 to the latest, with critical CVEs identified.
  • Immediate patching is recommended to prevent potential exploitation through the web UI or API.

Recent advisories reveal multiple vulnerabilities in Pi-hole's configuration system, allowing authenticated users to bypass security checks and execute arbitrary code. The flaws stem from the Teleporter import feature, which lacks validation for configuration files, enabling malicious directives to be executed within the dnsmasq configuration. This includes the ability to run shell commands and execute scripts without prior access to the system. The vulnerabilities affect all versions of Pi-hole FTL from 6.0 to the latest release, with specific CVEs including GHSA-2794-hrj8-5jg9 and GHSA-ww5x-xx4x-qvjr. The issues were discovered during a code review and have not been publicly exploited yet, but the potential for exploitation is significant. Administrators are urged to apply patches immediately to mitigate these risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-21
Vulnerabilities disclosed
Pi-hole disclosed multiple vulnerabilities allowing arbitrary code execution through configuration imports, affecting all versions from FTL 6.0.
github.com
2026-09-21
Advisory GHSA-ww5x-xx4x-qvjr published
Advisory details the vulnerability in the misc.dnsmasq_lines config option, allowing execution of arbitrary commands.
github.com

More articles in this cluster (2)