highVulnerability

GHSA-7549-ggpq-22w8

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-pr3g-phhr-h8fh. This link is maintained to preserve external references. ## Original Description LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful exploitation requires administrative privileges. Exploitation could result in compromise of the underlying web server.

Properties

ghsa_id
GHSA-7549-ggpq-22w8
summary
Duplicate Advisory: LibreNMS is Vulnerable to Remote Code Execution by Arbitrary File Write
severity
high
cve_id
GHSA-7549-ggpq-22w8
is_ghsa_only
true
ghsa_published
2026-04-13T12:31:15Z
source_url
https://github.com/advisories/GHSA-7549-ggpq-22w8
ghsa_updated
2026-04-14T22:51:57Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/librenms/librenms

AFFECTS (1)

[Software]composer/librenms/librenms

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-7549-ggpq-22w8 — Ninja Signal Threat Intelligence | Ninja Signal