Impact
LibreNMS versions up to 26.4.0 improperly render JSON fields—such as name, IP, model, author, and commit message—returned through the admin‑configurable Oxidized integration URL into the device showconfig page without applying escaping. This flaw permits a form of stored cross‑site scripting that can compromise the browser environment of any user who views a device’s showconfig tab. The vulnerability is classified as CWE‑79, a classic input validation flaw that leads to injected script execution.
Affected Systems
The affected product is LibreNMS, any instance running a version prior to 26.7.0. Administrators who configure the Oxidized integration URL without proper validation are specifically at risk. No other vendors or external applications are impacted by this issue.
Risk and Exploitability
The CVSS score is 9.2, indicating high severity. The EPSS score is not available, so the exploitation likelihood cannot be quantified from public data. The vulnerability is not listed in the CISA KEV catalog, but its nature—stored XSS via a configurable external service—highlights a strong attack vector for insiders or compromised administrators. An attacker must first obtain administrator privileges to point the Oxidized URL to a malicious server; once done, the malicious JSON is stored and subsequently delivered to all users who view the showconfig page, leading to malicious script execution with the privileges of the affected users.
OpenCVE Enrichment