CVE-2025-55296

librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0) in the Alert Template creation feature. This allows a user with the admin role to inject malicious JavaScript, which will be executed when the template is rendered, potentially compromising other admin accounts. This vulnerability is fixed in 25.8.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*

History

10 Sep 2025, 14:23

Type Values Removed Values Added
References () https://github.com/librenms/librenms/commit/8ade3d827d317f5ac4b336617aafff865f825958 - () https://github.com/librenms/librenms/commit/8ade3d827d317f5ac4b336617aafff865f825958 - Patch
References () https://github.com/librenms/librenms/security/advisories/GHSA-vxq6-8cwm-wj99 - () https://github.com/librenms/librenms/security/advisories/GHSA-vxq6-8cwm-wj99 - Vendor Advisory, Exploit
Summary
  • (es) LibreNMS es un sistema de monitorización de red comunitario con licencia GPL. Existe una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en LibreNMS (versión anterior a la 25.6.0) en la función de creación de plantillas de alerta. Esto permite que un usuario con rol de administrador inyecte JavaScript malicioso, que se ejecutará al renderizar la plantilla, lo que podría comprometer otras cuentas de administrador. Esta vulnerabilidad se ha corregido en la versión 25.8.0.
CPE cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*
First Time Librenms
Librenms librenms

18 Aug 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-18 18:15

Updated : 2025-09-10 14:23


NVD link : CVE-2025-55296

Mitre link : CVE-2025-55296

CVE.ORG link : CVE-2025-55296


JSON object : View

Products Affected

librenms

  • librenms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')