Cross-site scripting in LibreNMS - CVE-2025-62412

 

Cross-site scripting in LibreNMS - CVE-2025-62412

Published: April 24, 2026


Vulnerability identifier: #VU127439
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2025-62412
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to inject arbitrary script code.

The vulnerability exists due to improper neutralization of input during web page generation in the alert-rules functionality when handling alert rule creation or update requests. A remote privileged user can submit a crafted alert rule name to inject arbitrary script code.

The issue can be triggered by using XML character references that bypass sanitization and are later decoded when the alert rule list is rendered.


Affected software

LibreNMS

How to mitigate CVE-2025-62412

Install security update from vendor's website.

LibreNMS - update to 25.10.0

External References

Related Security Bulletins