Highlights
Auth Bypass: 34 prior fixes. Scrutinize any change in this area.
modules/luci-base/luasrc/dispatcher.lua: most-fixed (10 issues). Treat as high-risk during review.
106 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Auth Bypass: 34 fixes target authentication bypass, spanning session handling, ACL grants, and login logic, indicating a pervasive and recurring weakness in access control enforcement.
Command Injection: 20 fixes address command injection, often from unquoted user input in system(), popen(), or os.execute() calls, showing a systematic lack of safe shell invocation.
CSRF: 14 CSRF fixes show a systematic gap in enforcing POST and token checks on state-changing actions, many in service control endpoints.