Impact
LibreNMS versions up to 26.4.0 store the graph_descr configuration value, which is later rendered directly in page output without HTML escaping. An attacker who can create or edit a graph description within the admin interface can inject a malicious script that runs in the browser of any authenticated user who views the affected graph type. This stored XSS flaw (CWE‑79) can lead to theft of user credentials, session hijacking, or defacement of the web interface.
Affected Systems
The vulnerability exists in librenms:librenms releases <= 26.4.0. It is fixed in version 26.7.0 and later. Systems running older releases that allow an administrator to configure graph descriptions are susceptible.
Risk and Exploitability
With a CVSS score of 4.8 the risk is considered moderate. The exploit is not publicly available (EPSS not provided) and the issue is not listed in the CISA KEV catalog. Successful exploitation requires administrative privileges to set the graph description, after which any authenticated user who accesses that graph will be exposed to the injected script. The attack surface is therefore limited to environments where administrators can edit graph settings.
OpenCVE Enrichment