Command injection in LibreNMS - #VU134530
Published: June 15, 2026
LibreNMS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to command injection in the Signal alert transport module and scripts/composer_wrapper.php when adding and testing an alert transport entry with crafted Path and Recipient values. A remote user can supply specially crafted transport settings to execute arbitrary code.
Exploitation requires administrative access to create and test an alert transport entry.