CVE-2026-84189
9.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Summary
LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page without applying htmlspecialchars(). An administrator who points the Oxidized URL at an attacker-controlled server (SSRF) can cause it to return malicious JSON, resulting in stored/persistent cross-site scripting affecting all users who view any device's showconfig tab. Fixed in 26.7.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| librenms | librenms | 0 < 26.7.0 | affected |
| librenms | librenms | 26.7.0 | unaffected |
Weaknesses
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
References
- https://github.com/librenms/librenms/security/advisories/GHSA-7gww-x7fh-jf9j
- https://www.vulncheck.com/advisories/librenms-before-26.7.0-stored-xss-via-oxidized-api
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.