highCVSS 8.1Vulnerability

GHSA-7gww-x7fh-jf9j

### Summary The Oxidized integration URL (`oxidized.url`) is admin-configurable. LibreNMS fetches device info and version history from that URL and renders JSON fields (`name`, `ip`, `model`, `author`, commit message) into HTML without `htmlspecialchars()`. An admin pointing the URL at an attacker-controlled server achieves persistent XSS affecting all users who view any device's showconfig tab. ### CVSS `CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N` — **8.1 High** ### Details ```php // includes/html/pages/device/showconfig.inc.php:276-278 echo '<li ...><strong>Node:</strong> ' . $node_info['name'] . '</li>'; echo '<li ...><strong>IP:</strong> ' . $node_info['ip'] . '</li>'; echo '<li ...><strong>Model:</strong> '. $node_info['model'] . '</li>'; // lines 349, 353: author and commit message also unescaped ``` ### Attack chain 1. Admin sets `oxidized.url` to `http://attacker.example.com/`. 2. Attacker server returns `{"name":"<img src=x onerror=alert(1)>","ip":"x","model":"x"}`. 3. Any user viewing any device showconfig tab triggers the XSS. ### PoC Mock Oxidized server confirmed in response: ``` [!!!] CONFIRMED — ...<strong>Node:</strong> <img src=x onerror="alert('SSRF-XSS-oxidized')">... ``` ### Fix ```php echo '<li ...><strong>Node:</strong> ' . htmlspecialchars($node_info['name'], ENT_QUOTES, 'UTF-8') . '</li>'; ``` Apply to all fields from `$node_info`, `$author`, `$msg`. ### Prerequisite Admin session. Oxidized integration must be enabled.

Properties

ghsa_id
GHSA-7gww-x7fh-jf9j
severity
high
summary
LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page
cvss_score
8.1
cve_id
GHSA-7gww-x7fh-jf9j
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
is_ghsa_only
true
ghsa_published
2026-08-18T21:17:23Z
source_url
https://github.com/advisories/GHSA-7gww-x7fh-jf9j
ghsa_updated
2026-08-18T21:17:24Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]composer/librenms/librenms

AFFECTS (1)

[Software]composer/librenms/librenms

HAS_WEAKNESS (2)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-7gww-x7fh-jf9j (CVSS 8.1) — Ninja Signal Threat Intelligence | Ninja Signal