LibreNMS Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting (XSS) vulnerability has been identified in LibreNMS versions through 25.12.0. The issue arises in the email input field, where malicious scripts can be injected and executed. This vulnerability has been addressed in version 26.2.0.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Reproduction

To reproduce this vulnerability, navigate to the email settings page. In the email address input field, enter a payload that includes a script, such as an image tag with an 'onerror' event. This will trigger an alert displaying the document's cookies, demonstrating the successful execution of the injected script.

Remediation

Users can upgrade to LibreNMS version 26.2.0 or later to address this vulnerability.

Added: Feb 20, 2026, 2:42 AM
Updated: Feb 20, 2026, 2:42 AM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
1.7
exploitability
7.5
remediation
7.7
relevance
3.2
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.