CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-7CJ5-V4PP-V632

GHSA-7cj5-v4pp-v632: Stored Cross-Site Scripting in LibreNMS Graph Descriptions

Alon Barad
Alon Barad
Software Engineer

Aug 19, 2026·5 min read·13 visits

Executive Summary (TL;DR)

An authenticated administrator can store arbitrary JavaScript in the configuration database via graph descriptions. The stored payload executes inside the browser session of any user viewing the associated graph pages.

LibreNMS versions prior to 26.7.0 are vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. An authenticated administrator can inject arbitrary HTML or JavaScript into graph descriptions via specific administrative configuration endpoints. When another authenticated user views the affected graph, the unescaped payload executes within their browser context.

Vulnerability Overview

LibreNMS is an open-source, auto-discovering PHP/MySQL-based network monitoring system that utilizes SNMP to discover and graph network infrastructure. To maintain robust reporting, the platform provides administrators with configuration options to customize descriptions and attributes of various graph types. This administrative capability exposes an attack surface when system configurations are rendered to other web session contexts.

The administrative settings for graph descriptions, mapped to graph_descr.<graphtype>, allow administrators to input arbitrary string configurations. These settings are subsequently queried and rendered dynamically when users navigate to different graph sections of the application.

This vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation). Because the application retrieves and outputs these descriptions verbatim to the DOM, an attacker with administrative privileges can store malicious payloads, which are executed automatically when other users load the associated graph dashboard.

Root Cause Analysis

The underlying vulnerability is located within the presentation layer of the application, specifically in the file includes/html/pages/graphs.inc.php at line 194. The application dynamically processes requests for various graph types by analyzing URL and request parameters stored inside the $vars array.

To display custom graph descriptions, the application uses the dynamic configuration retrieval method LibrenmsConfig::get('graph_descr.' . $vars['type']). This function queries the system database and returns the configured value for the specified graph type. The returned value is then passed directly to the standard output buffer.

The application fails to invoke sanitation, filtering, or context-aware escaping functions before displaying this data. Because the output mechanism lacks context-aware encoding, the user browser interprets any stored string containing HTML elements or executable JavaScript tags as functional code instead of plain text.

Code Analysis and Patch Assessment

The vulnerability is demonstrated by examining the execution flow in the unpatched version of includes/html/pages/graphs.inc.php:

// Vulnerable Code: includes/html/pages/graphs.inc.php (Line 194)
// The retrieved configuration string is echoed directly to the output buffer without escaping.
echo LibrenmsConfig::get('graph_descr.' . $vars['type']);

To resolve this vulnerability, developers introduced a security patch that forces strict output encoding on the retrieved data before it is written to the browser context:

// Patched Code: includes/html/pages/graphs.inc.php (Line 194)
// The output is processed by htmlspecialchars with ENT_QUOTES to sanitize special characters.
echo htmlspecialchars(LibrenmsConfig::get('graph_descr.' . $vars['type']), ENT_QUOTES, 'UTF-8');

The implementation of htmlspecialchars() with the ENT_QUOTES flag and UTF-8 encoding ensures that characters such as <, >, &, ", and ' are safely converted to their corresponding HTML entity equivalents. This prevents the browser from interpreting the injected string as executable HTML tags or event handlers, effectively neutralizing the injection vector.

The fix is robust and complete for this specific rendering location. However, security teams should verify that other configuration rendering paths within the LibreNMS application code apply the same strict output escaping methodologies.

Attack Methodology and Proof-of-Concept

Exploiting this vulnerability requires network connectivity to the LibreNMS administrative interface and valid administrator credentials. The attack consists of a two-stage process: payload injection (persistence) and payload execution (victim trigger).

During the injection phase, the administrator sends an authenticated PUT request to update the graph description configurations. The endpoint accepts raw configurations, including HTML tags and event handlers. The payload is successfully written to the system database.

PUT /settings/graph_descr.device_processor HTTP/1.1
Host: <target-ip>
Content-Type: application/json
X-Requested-With: XMLHttpRequest
Authorization: Bearer <token>
 
{"value": "<img src=x onerror=\"alert('ADV-15')\">"}

When a victim visits the graphs page associated with the modified graph type (in this case, device_processor), their browser issues a GET request. The server queries the database, extracts the unescaped payload, and embeds it directly into the HTML response body. The browser processes the broken image element, fails to load the source, and triggers the onerror JavaScript handler in the victim's session context.

GET /graphs?type=device_processor HTTP/1.1
Host: <target-ip>
Authorization: Bearer <victim-token>

Threat and Impact Assessment

The impact of a successful exploitation of this vulnerability is significant, despite requiring administrative privileges. While administrators already have elevated control over the platform, stored XSS allows them to cross session boundaries and execute actions in the context of other authenticated users.

In scenarios where multiple administrators manage a LibreNMS instance, a lower-trust administrator or a compromised administrative account can leverage this vulnerability to hijack sessions of other, higher-privileged system administrators. This facilitates privilege escalation and unauthorized operational actions.

Because the session cookies of other active users can be extracted via document.cookie (if HttpOnly is not enforced), an attacker can perform administrative actions on behalf of the victim. This includes modifying system configurations, managing users, or querying detailed network infrastructure data.

Remediation and Defensive Engineering

The primary remediation strategy is upgrading the LibreNMS installation to version 26.7.0 or higher. This release contains the necessary codebase patches to sanitize dynamic configurations before output rendering.

For deployments where immediate upgrading is not possible, security administrators can apply the manual source code modification to includes/html/pages/graphs.inc.php. Ensure that htmlspecialchars() is integrated on line 194.

In addition to patching, organizations should implement defense-in-depth measures such as a strict Content Security Policy (CSP). Restricting inline scripts via policies like script-src 'self' prevents the execution of arbitrary JavaScript injected into the DOM, mitigating the operational impact of stored XSS vulnerabilities.

Official Patches

LibreNMSOfficial advisory containing documentation on vulnerable parameters.

Technical Appendix

CVSS Score
4.8/ 10
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Affected Systems

LibreNMS prior to version 26.7.0

Affected Versions Detail

Product
Affected Versions
Fixed Version
librenms/librenms
LibreNMS
< 26.7.026.7.0
AttributeDetail
CWE IDCWE-79
Attack VectorNetwork
CVSS v3.1 Score4.8
Privileges RequiredHigh
User InteractionRequired
Exploit StatusProof-of-Concept
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1189Drive-by Compromise
Initial Access
T1059.007Command and Scripting Interpreter: JavaScript
Execution
T1539Steal Web Session Cookie
Credential Access
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The application does not neutralize or incorrectly neutralizes user-controlled input before it is placed in output that is used as a web page that is served to other users.

Known Exploits & Detection

GitHub Security AdvisoryAdvisory containing the Proof of Concept payload details and endpoints.

Vulnerability Timeline

Vulnerability disclosed, patch released, and Advisory GHSA-7cj5-v4pp-v632 published.
2026-08-18

References & Sources

  • [1]GitHub Advisory Database
  • [2]LibreNMS Version 26.7.0 Release
  • [3]LibreNMS Source Code Repository

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•1 day ago•GHSA-9Q4R-4842-93VW
7.7

GHSA-9Q4R-4842-93VW: Cross-Tenant SQL Injection in Trigger.dev TSQL Query Compiler

A critical cross-tenant SQL injection vulnerability exists in the TSQL query compiler of Trigger.dev, allowing authenticated users to bypass tenant isolation boundaries and read arbitrary ClickHouse analytics logs and execution payloads belonging to other organizations.

Alon Barad
Alon Barad
8 views•6 min read
•1 day ago•GHSA-4672-HWV6-GQ62
5.4

GHSA-4672-HWV6-GQ62: Cross-environment deployment cancellation in Trigger.dev

A logical authorization bypass vulnerability exists in Trigger.dev versions prior to 4.5.6. This flaw allows an authenticated client with a low-trust environment API key, such as development or staging, to cancel active worker deployments in a higher-trust environment like production within the same project. The vulnerability occurs because write operations on deployments were scoped solely by project identifier instead of environment identifier.

Alon Barad
Alon Barad
6 views•6 min read
•2 days ago•GHSA-JQMF-MX4F-HFR6
10.0

GHSA-JQMF-MX4F-HFR6: Multiple Remote Code Execution and Security Flaws in Vibe-Trading AI-Agent Pipeline

An in-depth technical analysis of multiple critical security flaws identified in the Vibe-Trading ecosystem (vibe-trading-ai). These issues range from unauthenticated remote command injection via agent tool executions to arbitrary Python execution through dynamic module loading and unsafe Jinja2 template autoescaping, allowing full system compromise.

Amit Schendel
Amit Schendel
15 views•7 min read
•2 days ago•GHSA-5RMQ-CHC7-M22F
7.5

GHSA-5RMQ-CHC7-M22F: Arbitrary File Read and Path Traversal in Vibe-Trading Platform

An arbitrary file read and path traversal vulnerability in the Vibe-Trading platform allows unauthenticated remote attackers to retrieve sensitive configuration files, API keys, and system secrets. The flaw stems from permissive directory checking in path validation tools and a complete lack of input sanitization in the document reader utility. Remediation was introduced in version 0.1.7 by implementing strict path allowlists, forcing user authentication, and dropping root execution privileges within the container environment.

Alon Barad
Alon Barad
7 views•6 min read
•2 days ago•GHSA-V2F8-6655-7GRJ
10.0

GHSA-v2f8-6655-7grj: Remote Code Execution and Authentication Bypass in vibe-trading-ai

The vibe-trading-ai package prior to version 0.1.7 contains multiple critical security vulnerabilities including unauthenticated remote code execution (RCE) via session message injection, missing authentication on read endpoints, unrestricted file upload, insecure CORS policies, and sensitive key disclosure. Because the application default settings failed open, ran as root within Docker, and bound to all interfaces, remote unauthenticated attackers could compromise host environments containing sensitive trading data.

Amit Schendel
Amit Schendel
11 views•6 min read
•2 days ago•CVE-2026-18140
7.5

CVE-2026-18140: Uncontrolled Recursion in aws-smithy-json Token Skipping Path

CVE-2026-18140 is a denial-of-service vulnerability in the Amazon aws-smithy-json Rust crate. Under-validation of recursion depth within the unknown-key skipping path allows a remote, unauthenticated attacker to cause stack exhaustion and process aborts by sending deeply nested JSON arrays.

Amit Schendel
Amit Schendel
9 views•6 min read