Cross-site scripting in LibreNMS - #VU140837
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to cross-site scripting in the device showconfig page when rendering Oxidized API response fields into HTML. A remote privileged user can configure the Oxidized integration URL to an attacker-controlled server and cause crafted response fields to be stored and rendered to execute arbitrary script in the victim's browser.
User interaction is required to view a device showconfig tab, and the Oxidized integration must be enabled.