Cross-site scripting in LibreNMS - #VU152693
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the Tools → Oxidized node list implemented by get_oxidized_nodes_list() when rendering Oxidized API fields and SNMP sysName values. A remote privileged user can inject crafted markup into these fields to execute arbitrary script in a victim's browser.
User interaction is required to view the affected node list.