PT-2026-84152 · Librenms · Librenms
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
LibreNMS versions prior to 26.7.0
Description
The software fails to apply
htmlspecialchars() when rendering JSON fields returned by the admin-configurable Oxidized integration URL (oxidized.url) on the device showconfig page. If an administrator points this URL to an attacker-controlled server, it can lead to Server-Side Request Forgery (SSRF) and the return of malicious JSON. This results in stored cross-site scripting (XSS), which affects all users who view the showconfig tab of any device.Recommendations
Update to version 26.7.0 or later.
Exploit
Fix
SSRF
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Librenms