Cross-site scripting in LibreNMS - #VU140843
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in an administrator's browser and disclose sensitive information.
The vulnerability exists due to cross-site scripting in legacy PHP template pages under includes/html/pages/ when rendering SNMP-sourced data without HTML escaping. A remote privileged user can inject crafted SNMP field values to execute arbitrary JavaScript in an administrator's browser and disclose sensitive information.
User interaction is required because an administrator must view an affected page. The issue was confirmed with exfiltration of SNMP community strings and CSRF tokens from the administrator's browser.