Command injection in LibreNMS - #VU134530

 

Command injection in LibreNMS - #VU134530

Published: June 15, 2026


Vulnerability identifier: #VU134530
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: LibreNMS Project
Affected software:
LibreNMS

Detailed vulnerability description

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to command injection in the Signal alert transport module and scripts/composer_wrapper.php when adding and testing an alert transport entry with crafted Path and Recipient values. A remote user can supply specially crafted transport settings to execute arbitrary code.

Exploitation requires administrative access to create and test an alert transport entry.


Remediation

Install security update from vendor's website.

Sources