Impact
LibreNMS versions prior to 26.5.0 render SNMP‑polling VRF fields without sanitization, allowing attackers who control a monitored network device to inject arbitrary JavaScript. The injection is stored and executed in the browser whenever any user views a VRF‑related page, satisfying CWE‑79 and enabling session hijacking, phishing, or credential theft. The vulnerability is a classic stored XSS that can compromise the integrity and confidentiality of user accounts and data accessed through the web interface.
Affected Systems
The affected product is LibreNMS, a network monitoring and performance analysis system. All releases before 26.5.0 are vulnerable; administrators should verify the version they are running and plan to upgrade to 26.5.0 or later.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. Because the exploit requires an attacker to control a monitored SNMP device and for a victim to view the VRF page, the likelihood of widespread exploitation is limited, and there is no EPSS data or KEV listing. The attack vector is inferred to be network‑side control over SNMP responses; a compromise of an SNMP community string or the device itself would provide the necessary payload injection. If an attacker can inject script into the VRF display, any authenticated or unauthenticated user who looks at the page will have the script executed in their browser.
OpenCVE Enrichment