Cross-site scripting in LibreNMS - #VU140841
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the VRF display pages when rendering SNMP-sourced VRF fields in HTML and JavaScript contexts. A remote attacker can supply specially crafted SNMP field values to execute arbitrary script in a victim's browser.
User interaction is required to view VRF-related pages.