Cross-site scripting in LibreNMS - CVE-2026-45694
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to cross-site scripting in LegacyController.php document.title JavaScript assignment when handling crafted Proxmox instance and vmid GET parameters. A remote user can send a specially crafted link to execute arbitrary script in the victim's browser.
User interaction is required, and the victim must follow a crafted link. An authenticated session is required.