GHSA-7gww-x7fh-jf9j
### Summary The Oxidized integration URL (`oxidized.url`) is admin-configurable. LibreNMS fetches device info and version history from that URL and renders JSON fields (`name`, `ip`, `model`, `author`, commit message) into HTML without `htmlspecialchars()`. An admin pointing the URL at an attacker-controlled server achieves persistent XSS affecting all users who view any device's showconfig tab. ### CVSS `CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N` — **8.1 High** ### Details ```php // includes/html/pages/device/showconfig.inc.php:276-278 echo '<li ...><strong>Node:</strong> ' . $node_info['name'] . '</li>'; echo '<li ...><strong>IP:</strong> ' . $node_info['ip'] . '</li>'; echo '<li ...><strong>Model:</strong> '. $node_info['model'] . '</li>'; // lines 349, 353: author and commit message also unescaped ``` ### Attack chain 1. Admin sets `oxidized.url` to `http://attacker.example.com/`. 2. Attacker server returns `{"name":"<img src=x onerror=alert(1)>","ip":"x","model":"x"}`. 3. Any user viewing any device showconfig tab triggers the XSS. ### PoC Mock Oxidized server confirmed in response: ``` [!!!] CONFIRMED — ...<strong>Node:</strong> <img src=x onerror="alert('SSRF-XSS-oxidized')">... ``` ### Fix ```php echo '<li ...><strong>Node:</strong> ' . htmlspecialchars($node_info['name'], ENT_QUOTES, 'UTF-8') . '</li>'; ``` Apply to all fields from `$node_info`, `$author`, `$msg`. ### Prerequisite Admin session. Oxidized integration must be enabled.
Properties
- ghsa_id
- GHSA-7gww-x7fh-jf9j
- severity
- high
- summary
- LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page
- cvss_score
- 8.1
- cve_id
- GHSA-7gww-x7fh-jf9j
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-08-18T21:17:23Z
- source_url
- https://github.com/advisories/GHSA-7gww-x7fh-jf9j
- ghsa_updated
- 2026-08-18T21:17:24Z
Related Entities (5)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph