Cross-site scripting in LibreNMS - #VU140842
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the VLAN name display page when rendering SNMP-sourced VLAN names in HTML. A remote attacker can supply a specially crafted VLAN name to execute arbitrary script in a victim's browser.
The advisory identifies this as an additional vulnerable entry point following the same SNMP-sourced data flow pattern.